Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2020-07-28 CVE-2020-15418 XXE vulnerability in Veeam ONE Firmware 10.0.0.0
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415.
network
low complexity
veeam CWE-611
7.5
2020-07-16 CVE-2020-3405 XXE vulnerability in Cisco Sd-Wan Firmware
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system.
network
low complexity
cisco CWE-611
7.3
2020-07-16 CVE-2020-4462 XXE vulnerability in IBM products
IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
8.2
2020-07-15 CVE-2020-12684 XXE vulnerability in Inetsoftware I-Net Clear Reports 19.0.287
XXE injection can occur in i-net Clear Reports 2019 19.0.287 (Designer), as used in i-net HelpDesk and other products, when XML input containing a reference to an external entity is processed by a weakly configured XML parser.
network
low complexity
inetsoftware CWE-611
critical
9.8
2020-07-15 CVE-2019-17637 XXE vulnerability in multiple products
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.
local
low complexity
eclipse debian CWE-611
7.1
2020-07-14 CVE-2020-4510 XXE vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
5.5
2020-07-14 CVE-2020-12025 XXE vulnerability in Rockwellautomation Studio 5000 Logix Designer 32.00/32.01/32.02
Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XXE) vulnerability, which may allow an attacker to view hostnames or other resources from the program.
local
low complexity
rockwellautomation CWE-611
3.3
2020-06-30 CVE-2020-5602 XXE vulnerability in Mitsubishielectric products
Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver.
network
low complexity
mitsubishielectric CWE-611
7.5
2020-06-23 CVE-2020-14940 XXE vulnerability in Herac Tuxguitar 1.5.4
An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4.
network
low complexity
herac CWE-611
7.5
2020-06-22 CVE-2020-14204 XXE vulnerability in IBI Webfocus Business Intelligence 8.0
In WebFOCUS Business Intelligence 8.0 (SP6), the administration portal allows remote attackers to read arbitrary local files or forge server-side HTTP requests via a crafted HTTP request to /ibi_apps/WFServlet.cfg because XML external entity injection is possible.
network
low complexity
ibi CWE-611
8.2