VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 56 of 67
  • CVE-2022-3338MedOct 18, 2022
    risk 0.35cvss 5.4epss 0.00

    An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack. This can be exploited by mimicking the Agent Handler call to ePO and passing the carefully…

  • CVE-2022-42301MedOct 3, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) injection attack through the nbars process.

  • CVE-2022-21282MedJan 19, 2022
    risk 0.35cvss 5.3epss 0.03

    Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable…

  • CVE-2021-3312MedOct 8, 2021
    risk 0.35cvss 6.5epss 0.01

    An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.

  • CVE-2020-5323MedJul 19, 2021
    risk 0.35cvss 5.4epss 0.01

    Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an injection vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to gain…

  • CVE-2021-32754MedJul 12, 2021
    risk 0.35cvss 5.3epss 0.01

    FlowDroid is a data flow analysis tool. FlowDroid versions prior to 2.9.0 contained an XML external entity (XXE) vulnerability that allowed an attacker who had control over the source/sink definition file in XML format to read files from external locations. In order for this to…

  • CVE-2021-22338MedJun 29, 2021
    risk 0.35cvss 5.3epss 0.01

    There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict operation to the input XML message. Attacker can send specific message to exploit this vulnerability, leading to the module denial of service.

  • CVE-2021-1530MedMay 6, 2021
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software could allow an authenticated, remote attacker to access sensitive information or cause a partial denial of service (DoS) condition on an affected system. This vulnerability is due…

  • CVE-2021-1369MedApr 29, 2021
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected device. This vulnerability is due to the improper handling of XML…

  • CVE-2020-2315MedNov 4, 2020
    risk 0.35cvss 6.5epss 0.01

    Jenkins Visualworks Store Plugin 1.1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2305MedNov 4, 2020
    risk 0.35cvss 6.5epss 0.01

    Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2304MedNov 4, 2020
    risk 0.35cvss 6.5epss 0.01

    Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2172MedApr 7, 2020
    risk 0.35cvss 6.5epss 0.01

    Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2014-3599MedNov 12, 2019
    risk 0.35cvss 6.5epss 0.01

    HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy

  • CVE-2019-0340MedAug 14, 2019
    risk 0.35cvss 5.4epss 0.01

    The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to Missing XML Validation vulnerability. This issue affects the file upload at multiple locations. An attacker can read local XXE files.

  • CVE-2019-0948MedJun 12, 2019
    risk 0.35cvss 4.7epss 0.13

    An information disclosure vulnerability exists in the Windows Event Viewer (eventvwr.msc) when it improperly parses XML input containing a reference to an external entity. An attacker who successfully exploited this vulnerability could read arbitrary files via an XML external…

  • CVE-2018-1801MedFeb 4, 2019
    risk 0.35cvss 5.3epss 0.02

    IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 through V8.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML…

  • CVE-2018-17889MedOct 8, 2018
    risk 0.35cvss 5.3epss 0.01

    In WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior when parsing project files, the XMLParser that ships with Wecon PIStudio is vulnerable to a XML external entity injection attack, which may allow sensitive information…

  • CVE-2017-7545MedJul 26, 2018
    risk 0.35cvss 6.5epss 0.03

    It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other…

  • CVE-2018-2401MedMar 14, 2018
    risk 0.35cvss 5.4epss 0.02

    SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrusted source resulting in an XML External Entity (XXE) vulnerability.