CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,254 vulnerabilities with CWE-611
CVE-2016-6059 HIGH
IBM InfoSphere Information Server - DoS
CVSS 8.1
CVE-2016-3027 MEDIUM
IBM Security Access Manager for Web 8.0 - XML External Entity Injection
CVSS 6.5
CVE-2016-2908 CRITICAL
IBM Security Access Manager 9.0 and 8.0 Firmware - XML External Entity Injection
CVSS 9.1
CVE-2016-10097 HIGH
ForgeRock OpenAM 10.1.0 - XML External Entity Injection via SAMLRequest Parameter
CVSS 7.5
CVE-2016-7460 CRITICAL
VMware vRealize Automation 6.x < 6.2.5 - XML External Entity Injection
CVSS 9.1
CVE-2016-7459 HIGH
VMware vCenter Server 5.5-6.0 - Authenticated XXE Injection via Log Browser, Distributed Switch, or Content Library
CVSS 7.7
CVE-2016-7458 MEDIUM
VMware vSphere Client 5.5-6.0 - XML External Entity Injection via External Entity Declaration
CVSS 5.8
CVE-2016-9181 HIGH
perl-Image-Info - XML External Entity Injection in SVG Parser
CVSS 7.1
CVE-2016-9180 CRITICAL
XML::Twig for Perl - XML External Entity Injection via expand_external_ents Option Bypass
CVSS 9.1
CVE-2016-5851 HIGH
python-docx < 0.8.6 - XML External Entity Injection via Crafted Document
CVSS 8.8
CVE-2016-4047 MEDIUM
Open-Xchange OX App Suite <7.8.1-rev8 - Info Disclosure
CVSS 4.3
CVE-2016-3055 HIGH
IBM FileNet Workplace 4.0.2 - Authenticated XML External Entity Injection
CVSS 8.1
CVE-2016-3033 HIGH
IBM AppScan Source 8.7-9.0.3.3 - Authenticated XML External Entity Injection
CVSS 8.1
CVE-2016-0284 MEDIUM
IBM Rational Software Architect Design Manager 4.0-4.0.7, 5.0-5.0.2, 6.0-6.0.2 - XXE Injection
CVSS 5.4
CVE-2016-9563 MEDIUM KEV
SAP NetWeaver AS JAVA 7.5 - Authenticated XML External Entity Injection via BPEM UWL Connection Provider
CVSS 6.5
CVE-2016-9318 MEDIUM
libxml2 < 2.9.4 - XML External Entity Injection
CVSS 5.5
CVE-2016-5971 HIGH
IBM Security Privileged Identity Manager Virtual Appliance <2.0.2 F...
CVSS 7.1
CVE-2016-6408 HIGH
Cisco Prime Home 5.2.0 - Info Disclosure
CVSS 7.5
CVE-2016-4264 HIGH
Adobe ColdFusion <11-Update 10 - Info Disclosure
CVSS 8.6
CVE-2016-5000 MEDIUM
Apache POI < 3.14 - XML External Entity Injection via XLSX2CSV Example
CVSS 5.5
CVE-2016-3974 CRITICAL
SAP NetWeaver Application Server Java 7.10-7.50 - XML External Entity Injection via ServerNodesWSService
CVSS 9.1
CVE-2015-10082 MEDIUM
libplist 1.12 - XML External Entity Reference
CVSS 5.5
CVE-2015-10029 MEDIUM
kelvinmo simplexrd <3.1.0 - XML External Entity Reference
CVSS 5.5
CVE-2015-8031 CRITICAL
Hudson <3.3.2 - XML External Entity Injection
CVSS 9.8
CVE-2015-7968 MEDIUM
SAP NetWeaver AS < - XML External Entity
CVSS 4.3
Details
Vulnerabilities 1,254