Vulnerabilities > Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

DATE CVE VULNERABILITY TITLE RISK
2021-06-28 CVE-2020-15303 XML Entity Expansion vulnerability in Infoblox Nios
Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564.
network
low complexity
infoblox CWE-776
4.0
2021-06-16 CVE-2021-32623 XML Entity Expansion vulnerability in Apereo Opencast
Opencast is a free and open source solution for automated video capture and distribution.
network
low complexity
apereo CWE-776
4.0
2021-05-26 CVE-2018-10868 XML Entity Expansion vulnerability in Redhat Certification 7.0
redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user to run a "Billion Laugh Attack" by replying to XMLRPC methods when getting the status of an host.
network
low complexity
redhat CWE-776
7.5
2021-01-29 CVE-2020-24665 XML Entity Expansion vulnerability in Hitachi Vantara Pentaho 7.0.0/8.0.0
The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains an XML Entity Expansion injection vulnerability, which allows an authenticated remote users to trigger a denial of service (DoS) condition.
network
low complexity
hitachi CWE-776
4.0
2021-01-14 CVE-2021-23926 XML Entity Expansion vulnerability in multiple products
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input.
network
low complexity
apache netapp debian oracle CWE-776
critical
9.1
2021-01-13 CVE-2021-1267 XML Entity Expansion vulnerability in Cisco Firepower Management Center
A vulnerability in the dashboard widget of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-776
4.0
2020-11-09 CVE-2020-27017 XML Entity Expansion vulnerability in Trendmicro Interscan Messaging Security Virtual Appliance 8.5.1.1516/9.0/9.1
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files.
network
low complexity
trendmicro CWE-776
4.0
2020-10-22 CVE-2020-25186 XML Entity Expansion vulnerability in We-Con Levistudiou
An XXE vulnerability exists within LeviStudioU Release Build 2019-09-21 and prior when processing parameter entities, which may allow file disclosure.
network
low complexity
we-con CWE-776
5.0
2020-09-01 CVE-2012-3340 XML Entity Expansion vulnerability in IBM Infosphere Guardium 8.0/8.0.1/8.2
IBM InfoSphere Guardium 8.0, 8.01, and 8.2 is vulnerable to XML external entity injection, caused by improper validation of user-supplied input.
network
low complexity
ibm CWE-776
4.0
2020-08-21 CVE-2020-24590 XML Entity Expansion vulnerability in Wso2 API Manager and API Microgateway
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
network
low complexity
wso2 CWE-776
6.4