VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 59 of 67
  • CVE-2021-28973MedApr 13, 2021
    risk 0.32cvss 4.9epss 0.01

    The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data that is parsed by insecurely configured software components, leading to XXE attacks.

  • CVE-2020-27017MedNov 9, 2020
    risk 0.32cvss 4.9epss 0.06

    Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must already have obtained product…

  • CVE-2020-8256MedSep 30, 2020
    risk 0.32cvss 4.9epss 0.03

    A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.

  • CVE-2020-15772MedSep 18, 2020
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. When configuring Gradle Enterprise to integrate with a SAML identity provider, an XML metadata file can be uploaded by an administrator. The server side processing of this file dereferences XML External Entities…

  • CVE-2020-3256MedMay 6, 2020
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) Software could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vulnerability, an…

  • CVE-2020-6187MedFeb 12, 2020
    risk 0.32cvss 4.9epss 0.01

    SAP NetWeaver (Guided Procedures), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document input from a compromised admin, leading to Denial of Service.

  • CVE-2019-15983MedJan 6, 2020
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vulnerability, an attacker would need administrative privileges on…

  • CVE-2019-20153MedJan 5, 2020
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) in v5.4. An XML external entity (XXE) vulnerability in the upload definition feature in definition_upload_attach.jsp allows authenticated remote attackers to read arbitrary files…

  • CVE-2019-9488MedSep 11, 2019
    risk 0.32cvss 4.9epss 0.01

    Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to a XML External Entity Attack. However, for the attack to be possible, the attacker must have root/admin access to a protected host which is authorized to communicate with the Deep…

  • CVE-2019-11519MedApr 25, 2019
    risk 0.32cvss 4.9epss 0.01

    Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen.

  • CVE-2019-1698MedFeb 21, 2019
    risk 0.32cvss 4.9epss 0.03

    A vulnerability in the web-based user interface of Cisco Internet of Things Field Network Director (IoT-FND) Software could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The vulnerability is due to improper…

  • CVE-2019-0265MedFeb 15, 2019
    risk 0.32cvss 4.9epss 0.02

    SLD Registration of ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. Fixed in versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT,KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22,…

  • CVE-2018-11719MedAug 30, 2018
    risk 0.32cvss 4.9epss 0.01

    Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow XXE.

  • CVE-2016-9491MedJul 13, 2018
    risk 0.32cvss 4.9epss 0.03

    ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored…

  • CVE-2026-40991MedJun 10, 2026
    risk 0.31cvss 5.9epss 0.00

    When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection attack when the documentation-generating…

  • CVE-2024-6961MedJul 21, 2024
    risk 0.31cvss 5.9epss 0.00

    RAIL documents are an XML-based format invented by Guardrails AI to enforce formatting checks on LLM outputs. Guardrails users that consume RAIL documents from external sources are vulnerable to XXE, which may cause leakage of internal file data via the SYSTEM entity.

  • CVE-2023-23926MedFeb 16, 2023
    risk 0.31cvss 5.9epss 0.01

    APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in the apoc.import.graphml procedure of APOC core plugin prior to version 5.5.0 and 4.4.0.14 (4.4 branch) in Neo4j graph database. XML External Entity (XXE)…

  • CVE-2021-45096MedDec 16, 2021
    risk 0.31cvss 4.7epss 0.01

    KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (.knwf), aka AP-17730.

  • CVE-2020-25817MedJun 8, 2021
    risk 0.31cvss 4.8epss 0.01

    SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utility is misused for purposes involving external or user…

  • CVE-2019-2861MedJul 23, 2019
    risk 0.31cvss 4.2epss 0.04

    Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion…