VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 55 of 69
  • CVE-2022-46300MedMar 21, 2023
    risk 0.36cvss 5.5epss 0.04

    Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

  • CVE-2022-45468MedMar 21, 2023
    risk 0.36cvss 5.5epss 0.02

    Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

  • CVE-2022-45121MedMar 21, 2023
    risk 0.36cvss 5.5epss 0.00

    Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

  • CVE-2022-43512MedMar 21, 2023
    risk 0.36cvss 5.5epss 0.00

    Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

  • CVE-2022-41696MedMar 21, 2023
    risk 0.36cvss 5.5epss 0.00

    Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

  • CVE-2023-22322MedJan 30, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Motion Pro is installed may…

  • CVE-2021-4311MedJan 9, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handler. The manipulation leads to xml external entity reference. The patch is identified as 31d442b9fb1d518128fd18f6e4d54e06c3d67793.…

  • CVE-2022-4818MedDec 28, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in Talend Open Studio for MDM. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file org.talend.mdm.core/src/com/amalto/core/storage/SystemStorageWrapper.java. The manipulation leads to xml external…

  • CVE-2022-45386MedNov 15, 2022
    risk 0.36cvss 5.5epss 0.00

    Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-2759MedAug 31, 2022
    risk 0.36cvss 5.5epss 0.01

    Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control,…

  • CVE-2020-14379MedAug 16, 2022
    risk 0.36cvss 5.6epss 0.00

    A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and information disclosure.

  • CVE-2022-1331MedMay 3, 2022
    risk 0.36cvss 5.5epss 0.01

    In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entities while processing specific project files, which may allow unauthorized information disclosure.

  • CVE-2022-0221MedApr 13, 2022
    risk 0.36cvss 5.5epss 0.01

    A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. This could be exploited to pass data from local files to a…

  • CVE-2022-1018MedApr 1, 2022
    risk 0.36cvss 5.5epss 0.02

    When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server,…

  • CVE-2021-44028MedDec 22, 2021
    risk 0.36cvss 5.5epss 0.03

    XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue to CVE-2018-1285.

  • CVE-2021-44147MedNov 22, 2021
    risk 0.36cvss 5.5epss 0.01

    An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files via a crafted XML/Excel document and perform server-side request forgery attacks.

  • CVE-2021-37178MedAug 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). An XML external entity injection vulnerability in the underlying XML parser could cause the affected application to disclose arbitrary files to remote attackers by loading a specially crafted…

  • CVE-2021-32972MedJul 9, 2021
    risk 0.36cvss 5.5epss 0.01

    Panasonic FPWIN Pro, all Versions 7.5.1.1 and prior, allows an attacker to craft a project file specifying a URI that causes the XML parser to access the URI and embed the contents, which may allow the attacker to disclose information that is accessible in the context of the…

  • CVE-2021-27492MedMay 27, 2021
    risk 0.36cvss 5.5epss 0.02

    When opening a specially crafted 3DXML file, the application containing Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior could disclose arbitrary files to remote attackers. This is because…

  • CVE-2020-28387MedMar 15, 2021
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < SE2021MP3). When opening a specially crafted SEECTCXML file, the application could disclose arbitrary files to remote attackers. This is because of the passing…