CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,250 vulnerabilities with CWE-611
CVE-2023-50168 HIGH
Pega Platform < 8.8.5 - XML External Entity Injection via PDF Generation
CVSS 7.7
CVE-2023-25926 MEDIUM
IBM Security Guardium Key Lifecycle Manager 3.0-4.1.1 - XML External Entity Injection
CVSS 5.5
CVE-2023-50380 MEDIUM
Apache Ambari <= 2.7.7 - XML External Entity Injection
CVSS 6.5
CVE-2023-52239 MEDIUM
Magic xpi Integration Platform 4.13.4 - XML External Entity Injection via onItemImport
CVSS 6.5
CVE-2023-32327 HIGH
IBM Security Verify Access 10.0.0.0-10.0.6.1 - XML External Entity Injection
CVSS 7.1
CVE-2023-4554 MEDIUM
OpenText AppBuilder 21.2-23.2 - Authenticated XML External Entity Injection
CVSS 4.9
CVE-2023-45139 HIGH
fonttools 4.28.2-4.42.9 - XML External Entity Injection via SVG Table Parsing
CVSS 7.5
CVE-2023-6149 MEDIUM
Qualys Jenkins Plugin for WAS <2.0.11 - SSRF
CVSS 5.7
CVE-2023-6147 MEDIUM
Qualys Jenkins Plugin <1.0.5 - SSRF
CVSS 5.7
CVE-2023-26999 CRITICAL
NetScout nGeniusOne <6.3.4 - RCE, DoS
CVSS 9.8
CVE-2023-52252 CRITICAL
Unified Remote 3.13.0 - Remote Code Execution via Remote Upload Endpoint
CVSS 9.8
CVE-2023-46265 CRITICAL
Ivanti Avalanche Smart Device Server - XML External Entity Request Forgery
CVSS 9.8
CVE-2023-6280 HIGH
52north WPS < 4.0.0-beta.11 - XML External Entity Injection via WebProcessingService Servlet
CVSS 7.2
CVE-2023-6836 MEDIUM
WSO2 API Manager < 3.0.0 - XML External Entity Injection
CVSS 4.6
CVE-2023-6721 HIGH
Repox - XML External Entity Injection in File Upload Function
CVSS 8.3
CVE-2023-6194 LOW
Eclipse Memory Analyzer <1.14.0 - Info Disclosure
CVSS 2.8
CVE-2023-49733 CRITICAL
Apache Cocoon 2.2.0-2.2.9 - XML External Entity Injection
CVSS 9.8
CVE-2023-49656 CRITICAL
Jenkins MATLAB Plugin < 2.11.1 - XML External Entity Injection
CVSS 9.8
CVE-2023-22274 HIGH
Adobe RoboHelp Server <11.4 - Info Disclosure
CVSS 7.5
CVE-2023-46590 HIGH
Siemens OPC UA Modelling Editor - XXE Injection
CVSS 7.5
CVE-2023-4218 MEDIUM
Eclipse IDE < 4.29 - XML External Entity Injection via Project File Parsing
CVSS 5.0
CVE-2023-5136 MEDIUM
TopoGrafix DataPlugin - Info Disclosure
CVSS 5.5
CVE-2023-46802 MEDIUM
e-Tax Software <=3.0.10 - XML External Entity File Disclosure
CVSS 5.5
CVE-2023-46502 CRITICAL
openCRX < 5.3.0 - XML External Entity Injection via Insecure DocumentBuilderFactory
CVSS 9.8
CVE-2023-43067 MEDIUM
Dell Unity <5.3 - XML External Entity Injection
CVSS 4.9
Details
Vulnerabilities 1,250