CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,254 vulnerabilities with CWE-611
CVE-2017-12216
HIGH
Cisco SocialMiner - XML External Entity Injection via Crafted XML File Import
CVSS 8.8
CVE-2017-9458
CRITICAL
Palo Alto Networks PAN-OS XML External Entity Injection in GlobalProtect Gateway Interface
CVSS 9.8
CVE-2017-1458
HIGH
IBM QRadar Network Security 5.4 - XML External Entity Injection
CVSS 8.1
CVE-2017-12069
HIGH
OPC Foundation UA .NET Sample Code <2017-03-21 - XXE
CVSS 8.2
CVE-2017-11272
HIGH
Adobe Digital Editions < 4.5.5 - Exposure of Sensitive Information
CVSS 7.5
CVE-2017-1192
HIGH
IBM Sterling B2B Integrator 5.2 - XXE
CVSS 8.2
CVE-2017-11390
HIGH
Trend Micro Control Manager 6.0 - XML External Entity Injection
CVSS 7.5
CVE-2017-1383
CRITICAL
IBM InfoSphere Information Server <11.5 - XXE
CVSS 9.1
CVE-2017-9233
HIGH
libexpat < 2.2.0 - XML External Entity Injection via Malformed External Entity Definition
CVSS 7.5
CVE-2017-11457
MEDIUM
SAP NetWeaver AS JAVA 7.5 - Authenticated XML External Entity Injection in com.sap.km.cm.ice
CVSS 6.5
CVE-2017-1219
MEDIUM
IBM BigFix Platform - XML External Entity Injection
CVSS 6.5
CVE-2017-7664
CRITICAL
Apache OpenMeetings 3.1.0 - Info Disclosure
CVSS 10.0
CVE-2017-1000061
HIGH
xmlsec <1.2.23 - Info Disclosure/DoS
CVSS 7.1
CVE-2017-1000021
HIGH
LogicalDoc CE <7.5.3 - Info Disclosure
CVSS 8.8
CVE-2017-8557
MEDIUM
Windows System Information Console - Information Disclosure via XML External Entity Injection
CVSS 5.5
CVE-2017-0170
MEDIUM
Windows Performance Monitor - XML External Entity Injection
CVSS 6.5
CVE-2017-1254
HIGH
IBM Security Guardium 10.0 - XML External Entity Injection
CVSS 7.1
CVE-2017-10670
CRITICAL
OSCI Transport Library 1.6.1 (Java) and 1.6 (.NET) - XML External Entity Injection via OSCI Message
CVSS 9.8
CVE-2017-1322
HIGH
IBM API Connect 5.0.6.0 - XML External Entity Injection
CVSS 8.2
CVE-2017-6662
HIGH
Cisco Prime Infrastructure 1.1-3.1.6 & Evolved Programmable Network Manager 1.2-2.1 - Authenticated RCE via XXE
CVSS 8.0
CVE-2017-9231
HIGH
Citrix XenMobile Server <10.5 - Info Disclosure
CVSS 7.5
CVE-2017-2308
MEDIUM
Juniper Networks Junos Space <16.1R1 - Info Disclosure
CVSS 6.5
CVE-2017-9295
MEDIUM
Hitachi Device Manager < 8.5.2 - Authenticated XML External Entity Injection
CVSS 6.5
CVE-2017-8913
HIGH
SAP NetWeaver AS JAVA 7.5 - Authenticated XML External Entity Injection in Visual Composer VC70RUNTIME
CVSS 8.8
CVE-2017-1289
HIGH
IBM SDK for Java Technology < 6 - XML External Entity Injection
CVSS 8.2
Details
Vulnerabilities
1,254