CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,253 vulnerabilities with CWE-611
CVE-2017-18110 MEDIUM
Atlassian Crowd < 3.0.2 and 3.1.0 - XML External Entity Injection via Backup Restore
CVSS 6.5
CVE-2017-9362 HIGH
ManageEngine ServiceDesk Plus <9312 - XML Injection
CVSS 8.8
CVE-2017-17762 HIGH
Episerver 7 - Blind XML External Entity Injection
CVSS 7.5
CVE-2017-8316 HIGH
IntelliJ IDEA < 2017.2.2 - XML External Entity Injection via AndroidManifest.xml
CVSS 7.5
CVE-2017-16349 HIGH
SAP Business Planning and Consolidation - XML External Entity Injection in Reporting Functionality
CVSS 8.1
CVE-2017-7464 HIGH
JBoss EAP 7.0 - SSRF/Info Disclosure
CVSS 8.7
CVE-2017-7545 MEDIUM
jbpmmigration 6.5 - Info Disclosure
CVSS 6.5
CVE-2017-7465 CRITICAL
JBoss Enterprise Application Platform - Remote Code Execution via XSLT Processing
CVSS 9.0
CVE-2017-3208 CRITICAL
WebORB for Java 5.1.1.0 - XML External Entity Injection via AMF3 Message Deserialization
CVSS 9.8
CVE-2017-3206 CRITICAL
Flamingo 2.2.0 - XML External Entity Injection via AMF3 Message Deserialization
CVSS 9.8
CVE-2017-2815 HIGH
OpenFire User Import Export Plugin 2.6.0 - Authenticated XML External Entity Injection
CVSS 8.1
CVE-2017-15691 MEDIUM
Apache UIMA < 2.10.2 - XML External Entity Injection
CVSS 6.5
CVE-2017-8315 HIGH
Eclipse IDE <= 2017.2.5 - XML External Entity Injection via AndroidManifest.xml
CVSS 7.5
CVE-2017-6323 HIGH
Symantec Management Console < 8.1 - XML External Entity Injection
CVSS 8.0
CVE-2017-7426 MEDIUM
NetIQ Identity Manager Plugins <4.6.1 - SSRF
CVSS 5.4
CVE-2017-18197 CRITICAL
mxGraph < 3.7.6 - XML External Entity Injection via SAXParserFactory
CVSS 9.8
CVE-2017-1758 HIGH
IBM Financial Transaction Manager 3.0.2-3.1.0 - XML External Entity Injection
CVSS 7.1
CVE-2017-7375 CRITICAL
libxml2 < 2.9.4 - XML External Entity Injection via Default Parser Flags
CVSS 9.8
CVE-2017-5828 HIGH
Aruba ClearPass Policy Manager 6.6.0-6.6.4 - XML External Entity Injection
CVSS 8.1
CVE-2017-14699 MEDIUM
ASUS DSL Router Firmware - Authenticated XML External Entity Injection via AiCloud UPDATEACCOUNT or PROPFIND Request
CVSS 6.5
CVE-2017-1666 HIGH
IBM Tivoli Key Lifecycle Manager 2.5-2.7 - XXE
CVSS 8.1
CVE-2017-1000477 HIGH
xmlbundle 0.1.7 - XML External Entity Injection
CVSS 7.5
CVE-2017-1000498 HIGH
AndroidSVG 1.2.2 - XML External Entity Injection in SVG Parser
CVSS 7.8
CVE-2017-1000497 CRITICAL
Pepperminty-Wiki 0.15 - XML External Entity Injection in getsvgsize Function
CVSS 9.8
CVE-2017-1000496 HIGH
Commsy 9.0.0 - XML External Entity Injection in Configuration Import
CVSS 8.8
Details
Vulnerabilities 1,253