CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,274 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 4 of 26
- CVE-2017-15725HIGHCVSS 7.5EG 7.52019-10-28
An XML External Entity Injection vulnerability exists in Dzone AnswerHub.
- CVE-2017-16349HIGHCVSS 8.1EG 8.12018-08-02
An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML external entity to be referenced, resulting in information disclosure and potential denial …
- CVE-2017-1666HIGHCVSS 8.1EG 8.12018-01-09
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory…
- CVE-2017-1758HIGHCVSS 7.1EG 7.12018-02-21
IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML Exter…
- CVE-2017-17762HIGHCVSS 7.5EG 7.52018-08-29
XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx.
- CVE-2017-18110MEDIUMCVSS 6.5EG 6.52019-03-29
The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability.
- CVE-2017-18111HIGHCVSS 8.7EG 8.72019-03-29
The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 before version 5.2.6 used an XML document builder that was vulnerable to XXE when consuming a client OAut…
- CVE-2017-18197CRITICALCVSS 9.8EG 9.82018-02-24
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
- CVE-2017-18438MEDIUMCVSS 6.3EG 6.32019-08-02
cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242).
- CVE-2017-20151CRITICALCVSS 5.5EG 9.82022-12-30
A vulnerability classified as problematic was found in iText RUPS. This vulnerability affects unknown code of the file src/main/java/com/itextpdf/rups/model/XfaFile.java. The manipulation leads to xml external entity reference. The patch i…
- CVE-2017-2308MEDIUMCVSS 6.5EG 6.52017-05-30
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device.
- CVE-2017-2815HIGHCVSS 8.1EG 8.12018-05-15
An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the retrieval of arbitrary files or denial of service. An authenticated attacker can send a cra…
- CVE-2017-3206CRITICALCVSS 9.8EG 9.82018-06-11
The Java implementation of AMF3 deserializers used by Flamingo amf-serializer by Exadel, version 2.2.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. If the XML parsing is handled incorrectly it…
- CVE-2017-3208CRITICALCVSS 9.8EG 9.82018-06-11
The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. If the XML parsing is handled incorrectly…
- CVE-2017-3548MEDIUMCVSS 6.5EG 6.52017-04-24
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows unauthenti…
- CVE-2017-3811MEDIUMCVSS 6.5EG 6.52017-03-17
An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc39165. Known Affected Re…
- CVE-2017-3839MEDIUMCVSS 4.3EG 4.32017-02-22
An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to have read access to part of the information stored in the affected syst…
- CVE-2017-5661HIGHCVSS 7.3EG 7.32017-04-18
In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploit…
- CVE-2017-5662HIGHCVSS 7.3EG 7.32017-04-18
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exp…
- CVE-2017-5828HIGHCVSS 8.1EG 8.12018-02-15
An arbitrary command execution vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.
- CVE-2017-5992HIGHCVSS 8.2EG 8.22017-02-15
Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.
- CVE-2017-6055HIGHCVSS 7.8EG 7.82017-02-17
XML external entity (XXE) vulnerability in eParakstitajs 3 before 1.3.9 and eParaksts Java lib before 2.5.13 allows remote attackers to read arbitrary files or possibly have unspecified other impact via a crafted edoc file.
- CVE-2017-6323HIGHCVSS 8.0EG 8.02018-04-16
The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is processed by a weakly configured XML parser. This attack may lea…
- CVE-2017-6344MEDIUMCVSS 5.9EG 5.92017-02-27
XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a crafted XML document.
- CVE-2017-6662HIGHCVSS 8.0EG 8.02017-06-26
A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored in the affected sy…
- CVE-2017-6895CRITICALCVSS 9.8EG 9.82017-03-23
USB Pratirodh allows remote attackers to conduct XML External Entity (XXE) attacks via XML data in usb.xml.
- CVE-2017-7375CRITICALCVSS 9.8EG 9.82018-02-19
A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, t…
- CVE-2017-7426CRITICALCVSS 5.4EG 9.12018-03-01
The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to leak information or cause denial of service attacks.
- CVE-2017-7457MEDIUMCVSS 5.0EG 5.02017-04-14
XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.
- CVE-2017-7464CRITICALCVSS 8.7EG 9.82018-07-27
It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML conte…
- CVE-2017-7465CRITICALCVSS 9.0EG 9.82018-06-27
It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw to cause remote code execution if they are able to provide XSLT content for parsing. Doing…
- CVE-2017-7503CRITICALCVSS 9.8EG 9.82017-05-18
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
- CVE-2017-7545MEDIUMCVSS 6.5EG 6.52018-07-26
It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application s…
- CVE-2017-7664CRITICALCVSS 10.0EG 10.02017-07-17
Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.
- CVE-2017-7907MEDIUMCVSS 6.6EG 6.62017-05-19
An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 and prior. An improperly restricted XML parser (with improper restriction of XML external entity reference, or XXE) may…
- CVE-2017-8040MEDIUMCVSS 6.5EG 6.52017-09-09
In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attack was discovered in the Single Sign-On service dashboard. Privileged users can in some cas…
- CVE-2017-8056MEDIUMCVSS 5.3EG 5.32017-04-22
WatchGuard Fireware v11.12.1 and earlier mishandles requests referring to an XML External Entity (XXE), in the XML-RPC agent. This causes the Firebox wgagent process to crash. This process crash ends all authenticated sessions to the Fireb…
- CVE-2017-8110CRITICALCVSS 10.0EG 10.02017-04-25
www.modified-shop.org modified eCommerce Shopsoftware 2.0.2.2 rev 10690 has XXE in api/it-recht-kanzlei/api-it-recht-kanzlei.php.
- CVE-2017-8315HIGHCVSS 7.5EG 7.52018-04-20
Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit the vulnerability by implementing malicious code on Androidmanifest.xml.
- CVE-2017-8316HIGHCVSS 7.5EG 7.52018-08-03
IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.
- CVE-2017-8557MEDIUMCVSS 5.5EG 5.52017-07-11
Windows System Information Console in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclos…
- CVE-2017-8710MEDIUMCVSS 5.5EG 5.52017-09-13
The Microsoft Common Console Document (.msc) in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1 allows an attacker to read arbitrary files via an XML external entity (XXE) declaration, due to the way that the Microsoft Common C…
- CVE-2017-8913HIGHCVSS 8.8EG 8.82017-05-23
The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtroot/com.sap.visualc…
- CVE-2017-8918MEDIUMCVSS 5.5EG 5.52017-09-12
XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file.
- CVE-2017-9095MEDIUMCVSS 5.5EG 5.52017-09-08
XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import.
- CVE-2017-9096HIGHCVSS 8.8EG 8.82017-11-08
The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.
- CVE-2017-9231HIGHCVSS 7.5EG 7.52017-06-16
XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors.
- CVE-2017-9233HIGHCVSS 7.5EG 7.52017-07-25
XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.
- CVE-2017-9295MEDIUMCVSS 6.5EG 6.52017-05-29
XXE vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to read arbitrary files.
- CVE-2017-9362HIGHCVSS 8.8EG 8.82019-03-25
ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →