CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,298 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 3 of 26
- CVE-2016-9563CRITICALCVSS 6.5EG 9.0⚠ KEV2016-11-23
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.
- CVE-2016-9691HIGHCVSS 8.6EG 8.62017-05-05
IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly s…
- CVE-2016-9698HIGHCVSS 8.1EG 8.12017-06-08
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive informat…
- CVE-2016-9706CRITICALCVSS 9.1EG 9.12017-02-15
IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerabil…
- CVE-2016-9707HIGHCVSS 8.1EG 8.12017-03-31
IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume…
- CVE-2016-9724HIGHCVSS 8.1EG 8.12017-03-07
IBM QRadar 7.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all …
- CVE-2016-9924CRITICALCVSS 9.8EG 9.82017-03-29
Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks.
- CVE-2017-0170MEDIUMCVSS 6.5EG 6.52017-07-11
Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vul…
- CVE-2017-1000021HIGHCVSS 8.8EG 8.82017-07-17
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.
- CVE-2017-1000061HIGHCVSS 7.1EG 7.12017-07-17
xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service
- CVE-2017-1000190CRITICALCVSS 9.1EG 9.12017-11-17
SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.
- CVE-2017-1000477HIGHCVSS 7.5EG 7.52018-01-03
XMLBundle version 0.1.7 is vulnerable to XXE attacks which can result in denial of service attacks.
- CVE-2017-1000496HIGHCVSS 8.8EG 8.82018-01-03
Commsy version 9.0.0 is vulnerable to XXE attacks in the configuration import functionality resulting in denial of service and possibly remote execution of code.
- CVE-2017-1000497CRITICALCVSS 9.8EG 9.82018-01-03
Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and possibly remote code execution
- CVE-2017-1000498HIGHCVSS 7.8EG 7.82018-01-03
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution
- CVE-2017-10617MEDIUMCVSS 5.0EG 5.02017-10-13
The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an attacker to retrieve sensitive system files. Affected releases are Juniper Networks Contrail 2.2 prior to 2.21.4; 3.0 prior…
- CVE-2017-10670CRITICALCVSS 9.8EG 9.82017-06-30
An XML External Entity (XXE) issue exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET), exploitable by sending a crafted standard-conforming OSCI message from within the infrast…
- CVE-2017-10889MEDIUMCVSS 4.3EG 4.32017-11-17
TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.
- CVE-2017-1103HIGHCVSS 8.1EG 8.12017-05-10
IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or cons…
- CVE-2017-11272HIGHCVSS 7.5EG 7.52017-08-11
Adobe Digital Editions 4.5.4 and earlier has a security bypass vulnerability.
- CVE-2017-11286HIGHCVSS 7.5EG 7.52017-12-01
Adobe ColdFusion has an XML external entity (XXE) injection vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.
- CVE-2017-11390HIGHCVSS 7.5EG 7.52017-08-02
XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly ZDI-CAN-4706.
- CVE-2017-11457MEDIUMCVSS 6.5EG 6.52017-07-25
XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request, …
- CVE-2017-1149HIGHCVSS 8.1EG 8.12017-04-25
IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensiti…
- CVE-2017-1192HIGHCVSS 8.2EG 8.22017-08-10
IBM Sterling B2B Integrator 5.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources.…
- CVE-2017-12069HIGHCVSS 8.2EG 8.22017-08-30
An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATI…
- CVE-2017-1219MEDIUMCVSS 6.5EG 6.52017-07-19
IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force…
- CVE-2017-12216HIGHCVSS 8.8EG 8.82017-09-07
A vulnerability in the web-based user interface of Cisco SocialMiner could allow an unauthenticated, remote attacker to have read and write access to information stored in the affected system. The vulnerability is due to improper handling …
- CVE-2017-1254HIGHCVSS 7.1EG 7.12017-07-05
IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X…
- CVE-2017-12620CRITICALCVSS 9.8EG 9.82017-10-03
When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to …
- CVE-2017-12621CRITICALCVSS 9.8EG 9.82017-09-28
During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used in the body of the Jelly file, during parser instantiation the parser will attempt to conn…
- CVE-2017-12623MEDIUMCVSS 6.5EG 6.52017-10-10
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. …
- CVE-2017-12629CRITICALCVSS 9.8EG 9.82017-10-14
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses L…
- CVE-2017-1289HIGHCVSS 8.2EG 8.22017-05-22
IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X…
- CVE-2017-1322HIGHCVSS 8.2EG 8.22017-06-27
IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-F…
- CVE-2017-13706CRITICALCVSS 9.9EG 9.92017-10-10
XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote authenticated users to obtain sensitive information, cause a denial of service, conduct serv…
- CVE-2017-1383CRITICALCVSS 9.1EG 9.12017-08-02
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume mem…
- CVE-2017-14101CRITICALCVSS 9.8EG 9.82017-12-15
A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesson Medical Imaging Company, which is now a Change Healthcare company. An unauthenticated us…
- CVE-2017-14526HIGHCVSS 8.8EG 8.82017-09-28
Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Administrator 7.2.0180.0055 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of service, or, …
- CVE-2017-14527HIGHCVSS 8.8EG 8.82017-09-28
Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Webtop 6.8.0160.0073 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of service, or, on Wind…
- CVE-2017-1458HIGHCVSS 8.1EG 8.12017-09-05
IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-F…
- CVE-2017-14699MEDIUMCVSS 6.5EG 6.52018-01-29
Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U…
- CVE-2017-14759CRITICALCVSS 9.8EG 9.82017-10-03
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to an XML External Entity vulnerability: /xFramework/services/QuickDoc.QuickDocHttpSoap11E…
- CVE-2017-1477HIGHCVSS 8.1EG 8.12017-11-13
IBM Security Access Manager Appliance 9.0.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resour…
- CVE-2017-14868HIGHCVSS 7.5EG 7.52017-11-30
Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension.
- CVE-2017-14949HIGHCVSS 7.5EG 7.52017-11-30
Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly consid…
- CVE-2017-1527HIGHCVSS 8.1EG 8.12017-09-26
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory res…
- CVE-2017-15280MEDIUMCVSS 5.5EG 5.52017-10-12
XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server or sending TCP requests to intranet hosts (aka SSRF), related to Umbraco.Web/umbraco.presen…
- CVE-2017-15639MEDIUMCVSS 6.5EG 6.52017-10-19
tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature.
- CVE-2017-15691MEDIUMCVSS 6.5EG 6.52018-04-26
In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, Apache uimaDUCC prior to 2.2.2, this vulnerability relates to an XML external entity expansion (XXE…
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →