CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,253 vulnerabilities with CWE-611
CVE-2020-24656 MEDIUM
Maltego < 4.2.12 - XML External Entity Injection
CVSS 6.5
CVE-2020-24591 MEDIUM
WSO2 Management Console - XML External Entity Injection via EventReceiver Updates
CVSS 6.5
CVE-2020-24589 CRITICAL
WSO2 API Manager < 3.1.0 and API Microgateway 2.2.0 - XML External Entity Injection
CVSS 9.1
CVE-2020-24052 CRITICAL
Moog EXVF5C-2 and EXVP7C2-3 Firmware - Unauthenticated XML External Entity Injection via DTD
CVSS 9.1
CVE-2020-4481 HIGH
IBM UrbanCode Deploy 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 - XML External Entity Injection
CVSS 8.2
CVE-2020-4377 CRITICAL
IBM Cognos Analytics 11.0 and 11.1 - XML External Entity Injection
CVSS 9.1
CVE-2020-4463 HIGH
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 - XML External Entity Injection
CVSS 8.2
CVE-2020-15419 HIGH
Veeam ONE 10.0.0.750_20200415 - Info Disclosure
CVSS 7.5
CVE-2020-15418 HIGH
Veeam ONE 10.0.0.750_20200415 - Info Disclosure
CVSS 7.5
CVE-2020-3405 HIGH
Cisco SD-WAN vManage Software - SSRF
CVSS 7.3
CVE-2020-4462 HIGH
IBM Sterling External Authentication Server and Sterling Secure Proxy - XML External Entity Injection
CVSS 8.2
CVE-2020-12684 CRITICAL
i-net Clear Reports 2019 19.0.287 - XXE Injection
CVSS 9.8
CVE-2020-4510 MEDIUM
IBM QRadar SIEM 7.3-7.4 - XML External Entity Injection
CVSS 5.5
CVE-2020-12025 LOW
Rockwell Automation Studio 5000 Logix Designer 32.00-32.02 - XML External Entity Injection
CVSS 3.3
CVE-2020-5602 HIGH
Mitsubishi Electoric FA Engineering Software - Path Traversal
CVSS 7.5
CVE-2020-14940 HIGH
TuxGuitar 1.5.4 - XML External Entity Injection in GPX Document Reader
CVSS 7.5
CVE-2020-14204 HIGH
WebFOCUS Business Intelligence 8.0 SP6 - XML External Entity Injection via Administration Portal
CVSS 8.2
CVE-2020-8541 MEDIUM
OX App Suite <7.10.3 - XSS
CVSS 6.5
CVE-2020-13883 MEDIUM
WSO2 API Manager <3.0.0, API Microgateway, IS as Key Manager <5.9.0 - XXE in Management Console
CVSS 6.7
CVE-2020-13692 HIGH
PostgreSQL JDBC Driver < 42.2.13 - XML External Entity Injection
CVSS 7.7
CVE-2020-4509 HIGH
IBM QRadar SIEM 7.3 and 7.4 - XML External Entity Injection
CVSS 7.6
CVE-2020-4246 HIGH
IBM Security Identity Governance and Intelligence 5.2.6 - XML External Entity Injection
CVSS 7.1
CVE-2020-2012 HIGH
Palo Alto Networks Pan-OS 7.1.0-7.1.25 - Unauthenticated XML External Entity Injection
CVSS 7.5
CVE-2020-11541 MEDIUM
TechSmith SnagIt 11.2.1-20.0.3 - XML External Entity Injection
CVSS 5.5
CVE-2020-12719 HIGH
WSO2 API Manager < 3.0.0 - XML External Entity Injection via EventPublisher Update
CVSS 7.2
Details
Vulnerabilities 1,253