CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,253 vulnerabilities with CWE-611
CVE-2018-18406 CRITICAL
Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179 - XML External Entity Injection in Audit Report Module
CVSS 9.9
CVE-2018-1845 HIGH
IBM InfoSphere Information Server 11.3, 11.5, 11.7 - XML External Entity Injection
CVSS 7.1
CVE-2018-20160 CRITICAL
Synacor Zimbra Collaboration Suite 8.7-8.8 - XML External Entity Injection via ZxChat Mailboxd Request
CVSS 9.8
CVE-2018-8940 CRITICAL
Enghouse Cloud Contact Center Platform 7.2.5 - XML External Entity Injection via ClientServiceConfigController
CVSS 9.8
CVE-2018-14485 CRITICAL
BlogEngine.NET 3.3 - XML External Entity (XXE)
CVSS 9.8
CVE-2018-17169 HIGH
PrinterOn < 4.1.4 - Authenticated XML External Entity Injection
CVSS 7.7
CVE-2018-17289 MEDIUM
Kofax Front Office Server 4.1.1.11.0.5212 - Authenticated XML External Entity Injection via Package Configuration Upload
CVSS 6.5
CVE-2018-20222 CRITICAL
Airsonic <10.1.2 - XML External Entity Injection
CVSS 9.8
CVE-2018-1727 HIGH
IBM InfoSphere Information Server 9.1, 11.3, 11.5, 11.7 - XML External Entity Injection
CVSS 7.1
CVE-2018-1970 HIGH
IBM Security Identity Manager 7.0.1 - XXE
CVSS 7.1
CVE-2018-1801 MEDIUM
IBM App Connect 11.0.0.0 - XML External Entity Injection
CVSS 5.3
CVE-2018-19858 HIGH
PrinceXML < 10.0 - XML External Entity Injection via HTML IFRAME Element
CVSS 8.6
CVE-2018-20233 MEDIUM
Atlassian Universal Plugin Manager <2.22.14 - SSRF
CVSS 6.5
CVE-2018-2019 HIGH
IBM Security Identity Manager 6.0.0 Virtual Appliance - XML External Entity Injection
CVSS 7.1
CVE-2018-20733 HIGH
SAS Web Infrastructure Platform < 9.4M6 - XML External Entity Injection
CVSS 7.5
CVE-2018-16166 HIGH
LogonTracer < 1.2.0 - XML External Entity Injection
CVSS 8.8
CVE-2018-11788 CRITICAL
Apache Karaf < 4.1.7 and 4.2.0-4.2.2 - XML External Entity Injection via Features XML Deployer
CVSS 9.8
CVE-2018-20664 CRITICAL
ManageEngine ADSelfService Plus 5.x < 5701 - XML External Entity Injection via License Upload
CVSS 9.8
CVE-2018-19371 MEDIUM
SDL Web Content Manager 8.5.0 - XML External Entity Injection via SaveUserSettings Service
CVSS 6.5
CVE-2018-14720 CRITICAL
FasterXML jackson-databind 2.6.0-2.6.7.1 - XML External Entity Injection via Polymorphic Deserialization
CVSS 9.8
CVE-2018-1000889 HIGH
Logisim Evolution <2.14.3 - Info Disclosure
CVSS 8.8
CVE-2018-7837 HIGH
Schneider Electric IIoT Monitor 3.1.38 - XML External Entity Injection
CVSS 7.5
CVE-2018-20433 CRITICAL
Mchange C3p0 < 0.9.5.3 - XXE
CVSS 9.8
CVE-2018-20318 CRITICAL
.weixin-java-tools <3.2.0 - Info Disclosure
CVSS 9.8
CVE-2018-17247 MEDIUM
Elasticsearch Security 6.5.0-6.5.1 - Info Disclosure
CVSS 5.9
Details
Vulnerabilities 1,253