CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,253 vulnerabilities with CWE-611
CVE-2018-1000844 CRITICAL
Square Retrofit < 2.5.0 - XML External Entity Injection via JAXB
CVSS 9.1
CVE-2018-1000840 MEDIUM
Processing Foundation Processing <3.4 - XXE
CVSS 6.5
CVE-2018-1000838 CRITICAL
Autopsy <= 4.9.0 - XML External Entity Injection in CaseMetadata XML Parser
CVSS 10.0
CVE-2018-1000837 CRITICAL
UML Designer <= 8.0.0 - XML External Entity Injection via Plugins.xml
CVSS 10.0
CVE-2018-1000836 CRITICAL
bw-calendar-engine <= 3.12.0 - XML External Entity Injection in IscheduleClient XML Parser
CVSS 9.0
CVE-2018-1000835 CRITICAL
KeePassDX <= 2.5.0.0beta17 - XML External Entity Injection in KDBX File Parser
CVSS 10.0
CVE-2018-1000834 CRITICAL
runelite < 1.4.23 - XML External Entity Injection in Runescape Services Call
CVSS 9.0
CVE-2018-1000831 CRITICAL
K-9 Mail <= 5.600 - XML External Entity Injection in WebDAV Response Parser
CVSS 10.0
CVE-2018-1000830 CRITICAL
XR3Player <= 3.124 - XML External Entity Injection in Playlist Parser
CVSS 10.0
CVE-2018-1000829 CRITICAL
Anyplace - XML External Entity Injection via Map API Call
CVSS 9.0
CVE-2018-1000828 CRITICAL
FrostWire <= 6.7.4-build-272 - SSRF
CVSS 9.0
CVE-2018-1000825 CRITICAL
FreeCol <= nightly-2018-08-22 - XXE
CVSS 10.0
CVE-2018-1000823 CRITICAL
exist-db exist <= 5.0.0-RC4 - XML External Entity Injection in REST Server XML Parser
CVSS 10.0
CVE-2018-1000822 CRITICAL
codelibs fess < 12.2.3 and 12.3.0-12.3.1 - XML External Entity Injection in GSA XML File Parser
CVSS 10.0
CVE-2018-1000821 CRITICAL
MicroMathematics < 2.17.3 - XML External Entity Injection via SMathStudio Files
CVSS 10.0
CVE-2018-1000820 CRITICAL
neo4j-apoc-procedures <45bc09c - XSS
CVSS 10.0
CVE-2018-20298 MEDIUM
S3 Browser < 8.1.5 - XML External Entity Injection via S3 Protocol Connection
CVSS 6.5
CVE-2018-20157 HIGH
OpenRefine < 3.1 - XML External Entity Injection via Crafted Zip File
CVSS 7.5
CVE-2018-1821 HIGH
IBM Operational Decision Manager 8.6.0.0-8.6.0.2 - XML External Entity Injection
CVSS 7.1
CVE-2018-2492 HIGH
SAP NetWeaver AS Java - XML External Entity Injection in SAML 2.0
CVSS 7.1
CVE-2018-20059 CRITICAL
Pippo 1.11.0 - XML External Entity (XXE)
CVSS 9.8
CVE-2018-15805 CRITICAL
PrizmDoc < 13.5 - XML External Entity Injection
CVSS 9.1
CVE-2018-20000 HIGH
Apereo Bedework bw-webdav <4.0.3 - XML Injection
CVSS 7.5
CVE-2018-7063 HIGH
Aruba ClearPass Policy Manager < 6.6.10 - Unauthenticated XML External Entity Injection
CVSS 8.1
CVE-2018-1920 HIGH
IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 - XML External Entity Injection
CVSS 7.1
Details
Vulnerabilities 1,253