Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2020-03-10 CVE-2020-9044 XXE vulnerability in Johnsoncontrols products
XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files.
network
low complexity
johnsoncontrols CWE-611
6.4
2020-03-09 CVE-2020-2144 XXE vulnerability in Jenkins Rundeck
Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
7.1
2020-03-09 CVE-2020-2138 XXE vulnerability in Jenkins Cobertura
Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
7.1
2020-03-09 CVE-2015-7968 XXE vulnerability in SAP Netweaver Application Server
nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusion via the sap/bc/ui2/nwbc/nwbc_ext2int/ URI.
network
low complexity
sap CWE-611
4.0
2020-02-23 CVE-2020-9352 XXE vulnerability in Smartclient 12.0
An issue was discovered in SmartClient 12.0.
network
low complexity
smartclient CWE-611
critical
9.8
2020-02-17 CVE-2020-1693 XXE vulnerability in Redhat Spacewalk 1.6/2.6/2.9
A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint.
network
low complexity
redhat CWE-611
critical
9.8
2020-02-14 CVE-2019-6194 XXE vulnerability in Lenovo Xclarity Administrator
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow information disclosure.
network
lenovo CWE-611
4.3
2020-02-12 CVE-2020-1975 XXE vulnerability in Paloaltonetworks Pan-Os
Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary XML that results in privilege escalation.
network
low complexity
paloaltonetworks CWE-611
6.5
2020-02-12 CVE-2020-6187 XXE vulnerability in SAP Netweaver Guided Procedures
SAP NetWeaver (Guided Procedures), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document input from a compromised admin, leading to Denial of Service.
network
low complexity
sap CWE-611
4.0
2020-02-12 CVE-2020-2120 XXE vulnerability in Jenkins Fitnesse
Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
8.8