CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,254 vulnerabilities with CWE-611
CVE-2016-6059
HIGH
IBM InfoSphere Information Server - DoS
CVSS 8.1
CVE-2016-3027
MEDIUM
IBM Security Access Manager for Web 8.0 - XML External Entity Injection
CVSS 6.5
CVE-2016-2908
CRITICAL
IBM Security Access Manager 9.0 and 8.0 Firmware - XML External Entity Injection
CVSS 9.1
CVE-2016-10097
HIGH
ForgeRock OpenAM 10.1.0 - XML External Entity Injection via SAMLRequest Parameter
CVSS 7.5
CVE-2016-7460
CRITICAL
VMware vRealize Automation 6.x < 6.2.5 - XML External Entity Injection
CVSS 9.1
CVE-2016-7459
HIGH
VMware vCenter Server 5.5-6.0 - Authenticated XXE Injection via Log Browser, Distributed Switch, or Content Library
CVSS 7.7
CVE-2016-7458
MEDIUM
VMware vSphere Client 5.5-6.0 - XML External Entity Injection via External Entity Declaration
CVSS 5.8
CVE-2016-9181
HIGH
perl-Image-Info - XML External Entity Injection in SVG Parser
CVSS 7.1
CVE-2016-9180
CRITICAL
XML::Twig for Perl - XML External Entity Injection via expand_external_ents Option Bypass
CVSS 9.1
CVE-2016-5851
HIGH
python-docx < 0.8.6 - XML External Entity Injection via Crafted Document
CVSS 8.8
CVE-2016-4047
MEDIUM
Open-Xchange OX App Suite <7.8.1-rev8 - Info Disclosure
CVSS 4.3
CVE-2016-3055
HIGH
IBM FileNet Workplace 4.0.2 - Authenticated XML External Entity Injection
CVSS 8.1
CVE-2016-3033
HIGH
IBM AppScan Source 8.7-9.0.3.3 - Authenticated XML External Entity Injection
CVSS 8.1
CVE-2016-0284
MEDIUM
IBM Rational Software Architect Design Manager 4.0-4.0.7, 5.0-5.0.2, 6.0-6.0.2 - XXE Injection
CVSS 5.4
CVE-2016-9563
MEDIUM
KEV
SAP NetWeaver AS JAVA 7.5 - Authenticated XML External Entity Injection via BPEM UWL Connection Provider
CVSS 6.5
CVE-2016-9318
MEDIUM
libxml2 < 2.9.4 - XML External Entity Injection
CVSS 5.5
CVE-2016-5971
HIGH
IBM Security Privileged Identity Manager Virtual Appliance <2.0.2 F...
CVSS 7.1
CVE-2016-6408
HIGH
Cisco Prime Home 5.2.0 - Info Disclosure
CVSS 7.5
CVE-2016-4264
HIGH
Adobe ColdFusion <11-Update 10 - Info Disclosure
CVSS 8.6
CVE-2016-5000
MEDIUM
Apache POI < 3.14 - XML External Entity Injection via XLSX2CSV Example
CVSS 5.5
CVE-2016-3974
CRITICAL
SAP NetWeaver Application Server Java 7.10-7.50 - XML External Entity Injection via ServerNodesWSService
CVSS 9.1
CVE-2015-10082
MEDIUM
libplist 1.12 - XML External Entity Reference
CVSS 5.5
CVE-2015-10029
MEDIUM
kelvinmo simplexrd <3.1.0 - XML External Entity Reference
CVSS 5.5
CVE-2015-8031
CRITICAL
Hudson <3.3.2 - XML External Entity Injection
CVSS 9.8
CVE-2015-7968
MEDIUM
SAP NetWeaver AS < - XML External Entity
CVSS 4.3
Details
Vulnerabilities
1,254