CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,250 vulnerabilities with CWE-611
CVE-2023-22377 HIGH
tsClinical Define.xml Generator <1.4.0 - XXE
CVSS 7.4
CVE-2023-24187 HIGH
ureport v2.2.9 - XML External Entity Injection via Report File Upload
CVSS 7.8
CVE-2023-22832 HIGH
Apache NiFi 1.2.0-1.19.1 - XML External Entity Injection in ExtractCCDAAttributes Processor
CVSS 7.5
CVE-2023-24323 HIGH
mojoportal v2.7 - Authenticated XML External Entity Injection
CVSS 8.8
CVE-2023-22322 MEDIUM
OMRON CX-Motion Pro <1.4.6.013 - Info Disclosure
CVSS 5.5
CVE-2023-24443 CRITICAL
Jenkins TestComplete support Plugin <2.8.1 - XXE
CVSS 9.8
CVE-2023-24441 CRITICAL
Jenkins MSTest Plugin < 1.0.0 - XML External Entity Injection
CVSS 9.8
CVE-2023-24430 CRITICAL
Jenkins Semantic Versioning Plugin <1.14 - XXE
CVSS 9.8
CVE-2023-24429 CRITICAL
Jenkins Semantic Versioning Plugin <1.14 - SSRF
CVSS 9.8
CVE-2023-21862 HIGH
Oracle Fusion Middleware 12.2.1.4.0 - Unauthenticated RCE
CVSS 8.1
CVE-2023-22624 HIGH
ManageEngine Exchange Reporter Plus < 5708 - XML External Entity Injection
CVSS 7.5
CVE-2023-23595 HIGH
BlueCat Device Registration Portal 2.2 - XML External Entity Injection
CVSS 7.5
CVE-2022-50899 MEDIUM
GeoNetwork 3.10-4.2.0 - XML External Entity Injection via PDF Rendering
CVSS 6.5
CVE-2022-34832 MEDIUM
VERMEG AgileReporter 21.3 - XML External Entity Injection in Analysis Component
CVSS 6.5
CVE-2022-32755 MEDIUM
IBM Security Directory Server 6.4.0 - XML External Entity Injection
CVSS 5.5
CVE-2022-4245 MEDIUM
plexus-utils < 3.0.24 - XML External Entity Injection via Unsanitized Comment Handling
CVSS 4.3
CVE-2022-48565 CRITICAL
Python < 3.6.13 - XML External Entity Injection in plistlib Module
CVSS 9.8
CVE-2022-46751 HIGH
Apache Ivy < 2.5.2 - XML External Entity Injection via DTD Processing
CVSS 8.2
CVE-2022-41221 HIGH
OpenText Archive Center Administration <21.2 - XSS
CVSS 7.1
CVE-2022-45876 MEDIUM
VISAM VBASE < 11.7.5 - XML External Entity Injection
CVSS 5.5
CVE-2022-38840 HIGH
Gralp MAN-EAM-0003 3.2.4 - XML External Entity Injection via XML File Upload
CVSS 7.5
CVE-2022-43941 HIGH
Hitachi Vantara Pentaho Business Analytics Server <9.4.0.1-9.3.0.2 ...
CVSS 7.1
CVE-2022-43473 MEDIUM
ManageEngine OpManager <12.6.168 - SSRF
CVSS 5.8
CVE-2022-36969 HIGH
AVEVA Edge < 2020.2.00.40 - XML External Entity Injection via LoadImportedLibraries Method
CVSS 7.1
CVE-2022-46300 MEDIUM
VISAM VBASE Automation Base <11.7.5 - Info Disclosure
CVSS 5.5
Details
Vulnerabilities 1,250