CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,253 vulnerabilities with CWE-611
CVE-2018-11586 CRITICAL
SearchBlox 8.6.7 - Unauthenticated XML External Entity Injection via REST API Status Endpoint
CVSS 9.8
CVE-2018-1000198 MEDIUM
Jenkins Black Duck Hub Plugin <3.1.0 - SSRF
CVSS 6.5
CVE-2018-10613 HIGH
GE MDS PulseNET and MDS PulseNET Enterprise <= 3.2.1 - XML External Entity Injection
CVSS 7.5
CVE-2018-10653 CRITICAL
Citrix XenMobile Server <10.8 - XSS
CVSS 9.8
CVE-2018-1309 CRITICAL
Apache NiFi < 1.6.0 - XML External Entity Injection in SplitXML Processor
CVSS 9.8
CVE-2018-8010 MEDIUM
Apache Solr 6.0.0-6.6.3 and 7.0.0-7.3.0 - XML External Entity Injection in Config Files
CVSS 5.5
CVE-2018-4942 HIGH
Adobe ColdFusion - XML External Entity Injection
CVSS 7.5
CVE-2018-10832 MEDIUM
ModbusPal 1.6b - XML External Entity Injection via Crafted .xmpp or .xmpa Files
CVSS 5.5
CVE-2018-1259 HIGH
Spring Data Commons 1.13-1.13.11 & 2.0-2.0.6 - XXE via Projection-Based Request Binding
CVSS 7.5
CVE-2018-0765 HIGH
.NET and .NET Core - Denial of Service via XML Document Processing
CVSS 7.5
CVE-2018-1247 HIGH
RSA Authentication Manager < 8.3 - XML External Entity Injection via Malicious DTD
CVSS 7.1
CVE-2018-1183 CRITICAL
Dell EMC <8.4.0.8 - Info Disclosure
CVSS 9.8
CVE-2018-10175 MEDIUM
Digital Guardian Management Console <7.1.2.0015 - SSRF
CVSS 6.5
CVE-2018-10077 MEDIUM
Geist WatchDog Console 3.2.2 - Info Disclosure
CVSS 4.9
CVE-2018-1308 HIGH
Apache Solr 1.2-6.6.2 and 7.0.0-7.2.1 - XML External Entity Injection via DataImportHandler Inline XML Parameter
CVSS 7.5
CVE-2018-1421 HIGH
IBM WebSphere DataPower Appliances <7.6 - XXE
CVSS 7.1
CVE-2018-9116 CRITICAL
WireMock < 2.16.0 - Unauthenticated XML External Entity Injection
CVSS 9.1
CVE-2018-6225 MEDIUM
Trend Micro Email Encryption Gateway 5.5 - Authenticated XML External Entity Injection
CVSS 4.3
CVE-2018-2401 MEDIUM
SAP Business Process Automation By Redwood - XML External Entity Injection
CVSS 5.4
CVE-2018-1077 HIGH
Spacewalk 2.6 - XML External Entity Injection via API
CVSS 7.5
CVE-2018-0878 LOW
Windows Remote Assistance - Information Disclosure via XML External Entity Processing
CVSS 3.1
CVE-2018-1000124 CRITICAL
I Librarian I-librarian <4.8 - XML External Entity (XXE) SSRF
CVSS 10.0
CVE-2018-1000090 HIGH
textpattern 4.6.2 - Denial of Service via XML External Entity Injection in Import XML Feature
CVSS 7.5
CVE-2018-1000069 MEDIUM
FreePlane < 1.5.9 - XML External Entity Injection in Mindmap Loader
CVSS 5.5
CVE-2018-5758 MEDIUM
Aurea Jive-n 9.0.2.1 - XML External Entity Injection via Upload File Functionality
CVSS 6.5
Details
Vulnerabilities 1,253