CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,275 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 17 of 26
- CVE-2022-31775CRITICALCVSS 9.1EG 9.12022-08-01
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could explo…
- CVE-2022-32285HIGHCVSS 7.5EG 7.52022-06-14
A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mendix SAML Module (Mendix 8 compatible) (All versions < V2.2.2), Mendix SAML Module (Mendix 9 compatible) (All versions < V3.2.3). T…
- CVE-2022-32458HIGHCVSS 7.5EG 7.52022-07-20
Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection attack to access arbitrary system files.
- CVE-2022-32533CRITICALCVSS 9.8EG 9.82022-07-06
Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apa…
- CVE-2022-32755MEDIUMCVSS 5.5EG 5.52023-10-14
IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. I…
- CVE-2022-3338MEDIUMCVSS 5.4EG 5.42022-10-18
An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack. This can be exploited by mimicking the Agent Handler call…
- CVE-2022-3340HIGHCVSS 5.9EG 7.22022-11-04
XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in the administrator interface part of the interface, which allows a saved XML configuration …
- CVE-2022-34001MEDIUMCVSS 6.5EG 6.52022-07-19
Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.
- CVE-2022-34348HIGHCVSS 7.1EG 7.12022-09-23
IBM Sterling Partner Engagement Manager 6.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resou…
- CVE-2022-34793HIGHCVSS 8.8EG 8.82022-06-30
Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2022-34832MEDIUMCVSS 6.5EG 6.52023-10-27
An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component.
- CVE-2022-35168HIGHCVSS 7.5EG 7.52022-07-12
Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-service attack rendering the system temporarily inoperative.
- CVE-2022-35741CRITICALCVSS 9.8EG 9.82022-07-18
Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin is not enabled by default and the attacker would require th…
- CVE-2022-36773HIGHCVSS 8.1EG 8.12022-09-01
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory r…
- CVE-2022-36969HIGHCVSS 7.1EG 7.12023-03-29
This vulnerability allows remote attackers to disclose sensitive information on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must …
- CVE-2022-37189HIGHCVSS 7.5EG 7.52022-09-07
DDMAL MEI2Volpiano 0.8.2 is vulnerable to XML External Entity (XXE), leading to a Denial of Service. This occurs due to the usage of the unsafe 'xml.etree' library to parse untrusted XML input.
- CVE-2022-37911MEDIUMCVSS 3.8EG 5.52022-12-12
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the applicati…
- CVE-2022-38342HIGHCVSS 8.5EG 8.52022-09-13
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerability which allows authenticated attackers to perform data exfiltration or Server-Side Request Forgery (SSRF) attacks.
- CVE-2022-38389CRITICALCVSS 7.1EG 9.12023-02-03
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory …
- CVE-2022-38419HIGHCVSS 7.5EG 8.12022-10-14
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of th…
- CVE-2022-38840HIGHCVSS 7.5EG 7.52023-04-16
cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file disclosure.
- CVE-2022-39135CRITICALCVSS 9.8EG 9.82022-09-11
Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (…
- CVE-2022-3980CRITICALCVSS 9.8EG 9.82022-11-16
An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.
- CVE-2022-39954CRITICALCVSS 7.3EG 9.12023-02-16
An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, FortiNAC version 9.1.0 through 9.1.8, FortiNAC version 8.8.0 through 8.8.11, FortiNAC version …
- CVE-2022-40304HIGHCVSS 7.8EG 7.82022-11-23
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
- CVE-2022-40705HIGHCVSS 7.5EG 7.52022-09-22
An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files over HTTP. This issue affects Apache SOAP version 2.2 and later versions. It is unknown wh…
- CVE-2022-40747CRITICALCVSS 9.1EG 9.12022-11-03
"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources…
- CVE-2022-40771MEDIUMCVSS 4.9EG 4.92022-11-23
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure.
- CVE-2022-41221HIGHCVSS 7.1EG 7.12023-05-24
The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the applic…
- CVE-2022-41226CRITICALCVSS 9.8EG 9.82022-09-21
Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2022-41241CRITICALCVSS 9.1EG 9.12022-09-21
Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2022-41696MEDIUMCVSS 5.5EG 5.52023-03-21
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
- CVE-2022-41967HIGHCVSS 7.0EG 7.02022-12-28
Dragonfly is a Java runtime dependency management library. Dragonfly v0.3.0-SNAPSHOT does not configure DocumentBuilderFactory to prevent XML external entity (XXE) attacks. This issue is patched in 0.3.1-SNAPSHOT. As a workaround, since Dr…
- CVE-2022-42301HIGHCVSS 5.4EG 8.82022-10-03
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) injection attack through the nbars process.
- CVE-2022-42307CRITICALCVSS 5.3EG 9.82022-10-03
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service.
- CVE-2022-42341HIGHCVSS 7.5EG 7.72022-10-14
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of th…
- CVE-2022-4245MEDIUMCVSS 4.3EG 4.32023-09-25
A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allo…
- CVE-2022-42745HIGHCVSS 7.5EG 7.52022-11-03
CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because the application is vulnerable to XXE.
- CVE-2022-43415HIGHCVSS 7.5EG 7.52022-10-19
Jenkins REPO Plugin 1.15.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2022-43430HIGHCVSS 7.5EG 7.52022-10-19
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2022-43473MEDIUMCVSS 5.8EG 5.82023-03-30
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this v…
- CVE-2022-43512MEDIUMCVSS 5.5EG 5.52023-03-21
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
- CVE-2022-43570HIGHCVSS 8.8EG 8.82022-11-04
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect d…
- CVE-2022-43689MEDIUMCVSS 5.3EG 5.32022-11-14
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leading to IP disclosure.
- CVE-2022-43941HIGHCVSS 7.1EG 7.12023-04-03
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference…
- CVE-2022-45121MEDIUMCVSS 5.5EG 5.52023-03-21
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
- CVE-2022-45194MEDIUMCVSS 3.8EG 4.72022-11-12
CBRN-Analysis before 22 allows XXE attacks via am mws XML document, leading to NTLMv2-SSP hash disclosure.
- CVE-2022-45326MEDIUMCVSS 4.9EG 4.92022-12-06
An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks.
- CVE-2022-45386MEDIUMCVSS 5.5EG 5.52022-11-15
Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2022-45395CRITICALCVSS 9.8EG 9.82022-11-15
Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →