CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,253 vulnerabilities with CWE-611
CVE-2018-12408 HIGH
TIBCO ActiveMatrix BusinessWorks < - SSRF
CVSS 7.5
CVE-2018-14473 CRITICAL
OCS Inventory <2.4.1 - Denial of Service
CVSS 9.1
CVE-2018-13416 CRITICAL
Universal Media Server 7.1.0 - Unauthenticated XML External Entity Injection via SSDP/UPnP Parser
CVSS 9.8
CVE-2018-3881 CRITICAL
FocalScope v2416 - Unauthenticated XML External Entity Injection
CVSS 9.4
CVE-2018-8027 CRITICAL
Apache Camel 2.20.0-2.20.3 and 2.21.0 - XML External Entity Injection in XSD Validation Processor
CVSS 9.8
CVE-2018-10600 CRITICAL
SEL AcSELerator Architect <2.2.24.0 - Info Disclosure
CVSS 9.8
CVE-2018-14065 CRITICAL
PHPOffice Common <0.2.9 - XML Injection
CVSS 9.8
CVE-2018-12463 CRITICAL
HP Fortify Software Security Center 17.1, 17.2, 18.1 - Unauthenticated XML External Entity Injection via Crafted DTD
CVSS 9.8
CVE-2018-1000616 CRITICAL
ONOS < 1.13.1 - XML External Entity Injection in XmlConfigParser
CVSS 9.8
CVE-2018-1000614 CRITICAL
ONOS < 1.13.1 - Unauthenticated XML External Entity Injection in NetconfAlarmTranslator
CVSS 9.8
CVE-2018-13439 HIGH
WeChat Pay Java SDK - XML External Entity Injection via Merchant Notification URL
CVSS 7.5
CVE-2018-1542 HIGH
IBM FileNet Content Manager and Content Foundation - XML External Entity Injection
CVSS 7.1
CVE-2018-8026 MEDIUM
Apache Solr 6.0.0-6.6.4 and 7.0.0-7.3.1 - XML External Entity Injection via Config File Upload
CVSS 5.5
CVE-2018-11640 CRITICAL
Dialogic PowerMedia XMS < 3.5 - XML External Entity Injection
CVSS 9.1
CVE-2018-7783 HIGH
Schneider Electric SoMachine Basic <1.6 SP1 - SSRF
CVSS 7.5
CVE-2018-1000548 HIGH
Umlet < 14.3 - XML External Entity Injection via UXF File Parsing
CVSS 7.8
CVE-2018-1000546 HIGH
Triplea <=1.9.0.0.10291 - SSRF/Info Disclosure/RCE
CVSS 7.8
CVE-2018-1000542 HIGH
netbeans-mmd-plugin <=1.4.3 - SSRF/Info Disclosure/RCE
CVSS 7.8
CVE-2018-1000540 HIGH
LoboEvolution < 9b75694cedfa4825d4a2330abf2719d470c654cd - SSRF
CVSS 7.8
CVE-2018-1000515 HIGH
ventrian News-Articles <NewsArticles.00.09.11 - XML External Entity
CVSS 7.5
CVE-2018-8819 HIGH
Automated Logic WebCTRL 6.0, 6.1, 6.5 - Unauthenticated XML External Entity Injection via X-Wap-Profile Header
CVSS 7.5
CVE-2018-5434 MEDIUM
TIBCO Runtime Agent <= 5.10.0 and TIBCO Runtime Agent for z/Linux <= 5.9.1 - XML External Entity Injection
CVSS 5.8
CVE-2018-5433 MEDIUM
TIBCO Administrator <5.10.0 - Info Disclosure
CVSS 6.5
CVE-2018-6670 HIGH
McAfee Common UI < 2.0.3 - Authenticated XML External Entity Injection
CVSS 7.6
CVE-2018-1456 HIGH
IBM Rhapsody DM 5.0-5.0.2 and 6.0-6.0.5 - XML External Entity Injection
CVSS 7.1
Details
Vulnerabilities 1,253