CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,253 vulnerabilities with CWE-611
CVE-2019-11392 HIGH
BlogEngine.NET <3.3.7 - XML External Entity (XXE)
CVSS 7.5
CVE-2019-10718 HIGH
BlogEngine.NET < 3.3.7.0 - XML External Entity Injection via Pingback Handler
CVSS 7.5
CVE-2019-1903 MEDIUM
Cisco Security Manager - XML External Entity Injection via Malicious XML Requests
CVSS 6.5
CVE-2019-0948 MEDIUM
Windows Event Viewer - Info Disclosure
CVSS 4.7
CVE-2019-12154 CRITICAL
PDFreactor <10.1.10722 - Info Disclosure
CVSS 9.1
CVE-2019-10337 HIGH
Jenkins Token Macro Plugin < 2.7 - XML External Entity Injection via XML Macro
CVSS 7.5
CVE-2019-3722 HIGH
Dell EMC OpenManage Server Administrator < 9.1.0.3 and < 9.2.0.4 - Unauthenticated XML External Entity Injection
CVSS 7.5
CVE-2019-10327 HIGH
Jenkins Pipeline Maven Integration Plugin < 1.7.0 - XML External Entity Injection via Malicious XML File
CVSS 8.1
CVE-2019-9670 CRITICAL KEV
Synacor Zimbra Collaboration Suite <8.7.11p10 - XXE
CVSS 9.8
CVE-2019-0188 HIGH
Apache Camel < 2.24.0 - XML External Entity Injection in camel-xmljson Component
CVSS 7.5
CVE-2019-7442 CRITICAL
CyberArk Enterprise Password Vault <=10.7 - XXE
CVSS 9.8
CVE-2019-4208 HIGH
IBM TRIRIGA Application Platform 3.5.3-3.5.3.5 - XML External Entity Injection
CVSS 7.1
CVE-2019-11677 CRITICAL
Zoho ManageEngine Firewall Analyzer <12.3 Build 123224 - XXE Injection
CVSS 9.8
CVE-2019-10309 CRITICAL
Jenkins Self-Organizing Swarm Modules Plugin - XML External Entity Injection via UDP Broadcast Response
CVSS 9.3
CVE-2019-11519 MEDIUM
nopcommerce < 4.10 - XML External Entity Injection via Language Resource Import
CVSS 4.9
CVE-2019-8999 HIGH
BlackBerry Unified Endpoint Management < 12.10.1a - XML External Entity Injection
CVSS 7.5
CVE-2019-0228 CRITICAL
Apache PDFBox 2.0.14 - XML External Entity Injection via XFDF
CVSS 9.8
CVE-2019-0284 MEDIUM
SAP HANA - XML External Entity Injection via SLDREG
CVSS 6.0
CVE-2019-0795 HIGH
Microsoft Windows - Remote Code Execution via MSXML Parser
CVSS 8.8
CVE-2019-0793 HIGH
Microsoft Windows - Remote Code Execution via MSXML Parser
CVSS 8.8
CVE-2019-0792 HIGH
Microsoft Windows - Remote Code Execution via MSXML Parser
CVSS 8.8
CVE-2019-0791 HIGH
Microsoft Windows - Remote Code Execution via MSXML Parser
CVSS 8.8
CVE-2019-0790 HIGH
Microsoft Windows - Remote Code Execution via MSXML Parser
CVSS 8.8
CVE-2019-10244 HIGH
Eclipse Kura < 4.0.0 - XML External Entity Injection via Improper Parser Initialization
CVSS 7.5
CVE-2019-0756 HIGH
Microsoft Windows - XML External Entity Injection in MSXML Parser
CVSS 8.8
Details
Vulnerabilities 1,253