CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,252 vulnerabilities with CWE-611
CVE-2021-22498 HIGH
Micro Focus Application Lifecycle Management 12.x-12.60 Patch 5, 15.0.1 Patch 2, 15.5 - XML External Entity Injection
CVSS 8.1
CVE-2021-23899 CRITICAL
OWASP json-sanitizer < 1.2.2 - HTML and XML Injection via Crafted Input
CVSS 9.8
CVE-2021-21470 MEDIUM
SAP EPM Add-in 1010 & SAP Analysis Office 2.8 - Authenticated XXE in Logging Service
CVSS 4.4
CVE-2020-37192 MEDIUM
MSN Password Recovery 1.30 - Info Disclosure
CVSS 6.2
CVE-2020-26066 MEDIUM
Cisco SD-WAN vManage - Authenticated XML External Entity Injection via Crafted XML File Import
CVSS 6.5
CVE-2020-26064 HIGH
Cisco SD-WAN vManage Software - Authenticated XML External Entity Injection via XML File Import
CVSS 8.1
CVE-2020-26710 HIGH
easy-parse 0.1.1 - XML External Entity Injection via Crafted XML File
CVSS 7.5
CVE-2020-26709 HIGH
py-xml 1.0 - XML External Entity Injection via Crafted XML File
CVSS 7.5
CVE-2020-26708 HIGH
requests-xml 0.2.3 - XML External Entity Injection
CVSS 7.5
CVE-2020-36641 MEDIUM
gturri aXMLRPC <1.14.0 - XML External Entity Reference
CVSS 5.5
CVE-2020-36640 MEDIUM
bonitasoft bonita-connector-webservice <1.3.0 - SSRF
CVSS 5.5
CVE-2020-14379 MEDIUM
Redhat Jboss A-mq - XXE
CVSS 5.6
CVE-2020-21641 HIGH
Zoho ManageEngine Analytics Plus < 4.3.5 - XML External Entity Injection via Crafted License File
CVSS 7.5
CVE-2020-14478 HIGH
FactoryTalk Services Platform < 6.11.00 - Authenticated XML External Entity Injection
CVSS 7.1
CVE-2020-4876 HIGH
IBM Cognos Controller 10.4.0-10.4.2 - XML External Entity Injection
CVSS 8.2
CVE-2020-4875 HIGH
IBM Cognos Controller 10.4.0-10.4.2 - XML External Entity Injection
CVSS 8.2
CVE-2020-26705 CRITICAL
Easy-XML 0.5.0 - XML External Entity Disclosure or Denial of Service
CVSS 9.1
CVE-2020-25912 CRITICAL
Symphony CMS 2.7.10 - XML External Entity Disclosure or Denial of Service
CVSS 9.1
CVE-2020-25911 CRITICAL
MODX Revolution < 2.8.0 - XML External Entity Injection in modRestServiceRequest
CVSS 9.1
CVE-2020-19954 HIGH
S-CMS 3.0 - XML External Entity Arbitrary File Read
CVSS 7.5
CVE-2020-18705 CRITICAL
Quokka v0.4.0 - XML External Entity Injection in Content Views
CVSS 9.8
CVE-2020-18703 CRITICAL
Quokka v0.4.0 - XML External Entity Injection in quokka/utils/atom.py
CVSS 9.8
CVE-2020-26564 MEDIUM
ObjectPlanet Opinio <7.15 - XML External Entity
CVSS 6.5
CVE-2020-5323 MEDIUM
Dell EMC OpenManage Enterprise < 3.2 & OpenManage Enterprise-Modular < 1.10.00 - XXE Injection
CVSS 5.4
CVE-2020-5003 CRITICAL
IBM Financial Transaction Manager 3.2.4 - XML External Entity Injection
CVSS 9.1
Details
Vulnerabilities 1,252