CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,253 vulnerabilities with CWE-611
CVE-2018-7230 HIGH
Schneider Electric Pelco Sarix Professional < 3.29.67 - XML External Entity Injection via Web Interface Import
CVSS 8.8
CVE-2018-0218 LOW
Cisco Secure Access Control Server - XML External Entity Injection via Imported XML File
CVSS 3.3
CVE-2018-0207 LOW
Cisco Secure Access Control Server - XML External Entity Injection via Crafted XML File Import
CVSS 3.3
CVE-2018-6489 CRITICAL
Micro Focus Project and Portfolio Management Center 9.32 - XML External Entity Injection
CVSS 9.8
CVE-2018-2393 HIGH
SAP Internet Graphics Server 7.20, 7.20EXT, 7.45, 7.49, 7.53 - XML External Entity Injection
CVSS 7.5
CVE-2018-2392 HIGH
SAP Internet Graphics Server (IGS) XMLCHART XXE
CVSS 7.5
CVE-2018-1000056 HIGH
Jenkins JUnit Plugin <1.23 - SSRF/DoS
CVSS 8.3
CVE-2018-1000055 HIGH
Jenkins Android Lint Plugin <2.5 - SSRF/DoS
CVSS 8.3
CVE-2018-1000054 HIGH
Jenkins CCM Plugin < 3.1 - XML External Entity Injection in Build Process
CVSS 8.3
CVE-2018-3600 MEDIUM
Trend Micro Control Manager 6.0 - Info Disclosure
CVSS 6.5
CVE-2018-1307 HIGH
Apache jUDDI 3.2-3.3.4 - XML External Entity Injection via WADL2Java or WSDL2Java
CVSS 8.1
CVE-2018-5789 HIGH
Extreme Networks ExtremeWireless <5.8.6.9-5.9.1.3 - DoS
CVSS 7.5
CVE-2018-6486 HIGH
Micro Focus Fortify Audit Workbench and Software Security Center 16.10, 16.20, 17.10 - XML External Entity Injection
CVSS 7.3
CVE-2018-1364 HIGH
IBM Content Navigator 2.0 and 3.0 - XML External Entity Injection
CVSS 8.2
CVE-2018-1000012 HIGH
Jenkins Warnings Plugin < 4.64 - XML External Entity Injection
CVSS 8.8
CVE-2018-1000011 HIGH
Jenkins FindBugs Plugin < 4.71 - XML External Entity Injection in Build Process
CVSS 8.8
CVE-2018-1000010 HIGH
Jenkins DRY Plugin < 2.49 - Authenticated XML External Entity Injection
CVSS 8.8
CVE-2018-1000009 HIGH
Jenkins Checkstyle Plugin < 3.49 - XML External Entity Injection
CVSS 8.8
CVE-2018-1000008 HIGH
Jenkins PMD Plugin < 3.49 - XML External Entity Injection
CVSS 8.8
CVE-2018-0108 MEDIUM
Cisco WebEx Meetings Server - XML External Entity Injection
CVSS 5.3
CVE-2018-0100 MEDIUM
Cisco AnyConnect Secure Mobility Client - XML External Entity Injection via Profile Editor
CVSS 4.4
CVE-2017-20151 MEDIUM
iText RUPS - XML External Entity Reference
CVSS 5.5
CVE-2017-15725 HIGH
Dzone AnswerHub - XML External Entity Injection
CVSS 7.5
CVE-2017-18438 MEDIUM
cPanel 55.9999.61-64.0.20 - Authenticated Remote Code Execution via Encoding API
CVSS 6.3
CVE-2017-18111 HIGH
Atlassian Application Links <5.0.10, 5.1.0-5.1.3, 5.2.0-5.2.6 - XML External Entity Injection via OAuthHelper
CVSS 8.7
Details
Vulnerabilities 1,253