VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 54 of 69
  • CVE-2024-21796MedJan 24, 2024
    risk 0.36cvss 5.5epss 0.00

    Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creation Support Tool (Design & Survey Edition) prior to Ver1.0.4 improperly restrict XML external entity references (XXE). By processing a specially crafted XML…

  • CVE-2024-21765MedJan 24, 2024
    risk 0.36cvss 5.5epss 0.00

    Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delivery Check System (Kikai) Ver.10.1.0 and earlier, and Electronic delivery item Inspection Support SystemVer.4.0.31 and earlier…

  • CVE-2023-5136MedNov 8, 2023
    risk 0.36cvss 5.5epss 0.00

    An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulnerability by getting a user to open a specially crafted data file.

  • CVE-2023-46802MedNov 6, 2023
    risk 0.36cvss 5.5epss 0.00

    e-Tax software Version3.0.10 and earlier improperly restricts XML external entity references (XXE) due to the configuration of the embedded XML parser. By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.

  • CVE-2023-43624MedOct 23, 2023
    risk 0.36cvss 5.5epss 0.00

    CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML external entity reference (XXE) vulnerability. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where…

  • CVE-2022-32755MedOct 14, 2023
    risk 0.36cvss 5.5epss 0.01

    IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 228505.

  • CVE-2023-42132MedOct 2, 2023
    risk 0.36cvss 5.5epss 0.00

    FD Application Apr. 2022 Edition (Version 9.01) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.

  • CVE-2023-3892MedSep 19, 2023
    risk 0.36cvss 5.6epss 0.00

    Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client DICOM RTst Loading modules allows XML Entity Linking / XML External Entities Blowup. In order to take advantage of this vulnerability, an attacker must craft a malicious XML…

  • CVE-2023-24620MedAug 25, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expansion attack against YamlBeans YamlReader. By exploiting the Anchor feature in YAML, it is possible to generate a small YAML document that, when read, is…

  • CVE-2023-32639MedJul 25, 2023
    risk 0.36cvss 5.5epss 0.00

    Applicant Programme Ver.7.06 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.

  • CVE-2023-32635MedJul 19, 2023
    risk 0.36cvss 5.5epss 0.00

    XBRL data create application version 7.0 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XBRL file, arbitrary files on the system may be read by an attacker.

  • CVE-2023-37200MedJul 12, 2023
    risk 0.36cvss 5.5epss 0.00

    A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause loss of confidentiality when replacing a project file on the local filesystem and after manual restart of the server.

  • CVE-2023-3276MedJun 15, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this issue is the function readBySax of the file XmlUtil.java of the component XML Parsing Module. The manipulation leads to xml external entity reference. The…

  • CVE-2023-29498MedJun 13, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper restriction of XML external entity reference (XXE) vulnerability exists in FRENIC RHC Loader v1.1.0.3 and earlier. If a user opens a specially crafted project file, sensitive information on the system where the affected product is installed may be disclosed.

  • CVE-2023-2806MedMay 19, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the function RequestInfoByXml of the component API. The manipulation leads to xml external entity reference. The associated identifier of this vulnerability is…

  • CVE-2022-45876MedApr 26, 2023
    risk 0.36cvss 5.5epss 0.03

    Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

  • CVE-2023-27652MedApr 20, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the update_info field of the _default_.xml file.

  • CVE-2023-26264MedApr 13, 2023
    risk 0.36cvss 5.5epss 0.00

    All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code.

  • CVE-2023-26263MedApr 13, 2023
    risk 0.36cvss 5.5epss 0.00

    All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/license endpoint of the remote harvesting server.

  • CVE-2023-25955MedApr 11, 2023
    risk 0.36cvss 5.5epss 0.00

    National land numerical information data conversion tool all versions improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.