CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,275 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 7 of 26
- CVE-2018-16166HIGHCVSS 8.8EG 8.82019-01-09
LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
- CVE-2018-16252LOWCVSS 3.3EG 3.32018-09-05
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
- CVE-2018-16303HIGHCVSS 7.5EG 7.52018-09-01
PDF-XChange Editor through 7.0.326.1 allows remote attackers to cause a denial of service (resource consumption) via a crafted x:xmpmeta structure, a related issue to CVE-2003-1564.
- CVE-2018-16521CRITICALCVSS 9.8EG 9.82018-09-05
An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0.
- CVE-2018-1669HIGHCVSS 7.1EG 7.12018-09-25
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 are vulnerable to a XML External Entity I…
- CVE-2018-16792CRITICALCVSS 9.1EG 9.12018-12-05
SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.
- CVE-2018-1702HIGHCVSS 7.1EG 7.12018-09-28
IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expos…
- CVE-2018-17152MEDIUMCVSS 6.4EG 6.42019-07-11
Intersystems Cache 2017.2.2.865.0 allows XXE.
- CVE-2018-17169HIGHCVSS 7.7EG 7.72019-04-23
An XML external entity (XXE) vulnerability in PrinterOn version 4.1.4 and lower allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
- CVE-2018-17186HIGHCVSS 7.2EG 7.22018-11-06
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
- CVE-2018-17247MEDIUMCVSS 5.9EG 5.92018-12-20
Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could …
- CVE-2018-1727CRITICALCVSS 7.1EG 9.12019-02-15
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consu…
- CVE-2018-17289MEDIUMCVSS 6.5EG 6.52019-04-18
An XML external entity (XXE) vulnerability in Kofax Front Office Server Administration Console version 4.1.1.11.0.5212 allows remote authenticated users to read arbitrary files via crafted XML inside an imported package configuration (.ZIP…
- CVE-2018-1730HIGHCVSS 7.1EG 7.12018-12-05
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force…
- CVE-2018-17411CRITICALCVSS 9.8EG 9.82018-09-26
An XML External Entity (XXE) vulnerability exists in iWay Data Quality Suite Web Console 10.6.1.ga-2016-11-20.
- CVE-2018-1747HIGHCVSS 7.1EG 7.12018-10-15
IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume…
- CVE-2018-17889MEDIUMCVSS 5.3EG 5.32018-10-08
In WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior when parsing project files, the XMLParser that ships with Wecon PIStudio is vulnerable to a XML external entity injection attack, …
- CVE-2018-17912HIGHCVSS 7.5EG 7.52018-11-02
An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow remote file disclosure.
- CVE-2018-1801MEDIUMCVSS 5.3EG 5.32019-02-04
IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 through V8.0.0.9 is vulnerable to a XML External Entity In…
- CVE-2018-1821CRITICALCVSS 7.1EG 9.12018-12-13
IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or c…
- CVE-2018-1835HIGHCVSS 7.1EG 7.12018-11-02
IBM Daeja ViewONE Professional, Standard & Virtual 5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memo…
- CVE-2018-18406CRITICALCVSS 9.9EG 9.92019-06-19
An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE vulnerability when a new Best Practices Report is saved using a special payload inside the xml input …
- CVE-2018-1844HIGHCVSS 7.1EG 7.12018-10-12
IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resour…
- CVE-2018-1845HIGHCVSS 7.1EG 7.12019-06-17
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume me…
- CVE-2018-1846HIGHCVSS 7.1EG 7.12018-11-02
IBM Rational Engineering Lifecycle Manager 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensit…
- CVE-2018-18471CRITICALCVSS 9.8EG 9.82019-06-19
/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can be chained with an SSRF bug to gain remote command execution as root. It can be triggered…
- CVE-2018-18659HIGHCVSS 7.5EG 7.52018-10-26
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-19 Unauthenticated XXE in /management/UdpHttpService issue.
- CVE-2018-18737HIGHCVSS 7.5EG 7.52018-10-29
An XXE issue was discovered in Douchat 4.0.4 because Data\notify.php calls simplexml_load_string. This can also be used for SSRF.
- CVE-2018-18980HIGHCVSS 7.5EG 7.52018-11-06
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacke…
- CVE-2018-1905HIGHCVSS 7.1EG 7.12018-11-26
IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume …
- CVE-2018-1920HIGHCVSS 7.1EG 7.12018-12-07
IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resou…
- CVE-2018-19244HIGHCVSS 8.6EG 8.62018-11-13
An XML External Entity (XXE) vulnerability exists in the Charles 4.2.7 import/export setup option. If a user imports a "Charles Settings.xml" file from an attacker, an intranet network may be accessed and information may be leaked.
- CVE-2018-19371MEDIUMCVSS 6.5EG 6.52019-01-02
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.
- CVE-2018-1970HIGHCVSS 7.1EG 7.12019-02-04
IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM…
- CVE-2018-19858HIGHCVSS 8.6EG 8.62019-01-30
PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an attacker passes HTML referencing an XML file (e.g., in an IFRAME element), PrinceXML will fetch the XML and parse it, thu…
- CVE-2018-20000HIGHCVSS 7.5EG 7.52018-12-10
Apereo Bedework bw-webdav before 4.0.3 allows XXE attacks, as demonstrated by an invite-reply document that reads a local file, related to webdav/servlet/common/MethodBase.java and webdav/servlet/common/PostRequestPars.java.
- CVE-2018-20059CRITICALCVSS 9.8EG 9.82018-12-11
jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.
- CVE-2018-20157HIGHCVSS 7.5EG 7.52018-12-15
The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing attackers to read arbitrary files.
- CVE-2018-20160CRITICALCVSS 9.8EG 9.82019-05-29
ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and in other products, allows XXE attacks, as demonstrated by a crafted XML request to mailboxd.
- CVE-2018-2019HIGHCVSS 7.1EG 7.12019-01-18
IBM Security Identity Manager 6.0.0 Virtual Appliance is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume mem…
- CVE-2018-20222CRITICALCVSS 9.8EG 9.82019-04-04
XXE issue in Airsonic before 10.1.2 during parse.
- CVE-2018-20233MEDIUMCVSS 6.5EG 6.52019-01-18
The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privileges to read files, make network requests and perform a denial of service attack via an XML…
- CVE-2018-20298MEDIUMCVSS 6.5EG 6.52018-12-19
S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary files and obtain NTLMv2 hash values by tricking a user into connecting to a malicious server via the S3 protocol.
- CVE-2018-20318CRITICALCVSS 9.8EG 9.82018-12-21
An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file.
- CVE-2018-20433CRITICALCVSS 9.8EG 9.82018-12-24
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
- CVE-2018-20664CRITICALCVSS 9.8EG 9.82019-01-03
Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license.
- CVE-2018-20687CRITICALCVSS 9.8EG 9.82019-11-18
An XML external entity (XXE) vulnerability in CommandCenterWebServices/.*?wsdl in Raritan CommandCenter Secure Gateway before 8.0.0 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) a…
- CVE-2018-20733HIGHCVSS 7.5EG 7.52019-01-17
BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.
- CVE-2018-20843HIGHCVSS 7.5EG 7.52019-06-24
In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service att…
- CVE-2018-2392HIGHCVSS 7.5EG 7.82018-02-14
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →