Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2019-02-11 CVE-2019-7722 XXE vulnerability in PMD Project PMD
PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowing attackers tampering it (either by direct modification or MITM attacks when using remote rulesets) to perform information disclosure, denial of service, or request forgery attacks.
network
high complexity
pmd-project CWE-611
8.1
2019-02-06 CVE-2019-1003015 XXE vulnerability in Jenkins JOB Import
An XML external entity processing vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport/client/RestApiClient.java that allows attackers with the ability to control the HTTP server (Jenkins) queried in preparation of job import to read arbitrary files, perform a denial of service attack, etc.
network
low complexity
jenkins CWE-611
critical
9.1
2019-02-04 CVE-2018-1970 XXE vulnerability in IBM Security Access Manager
IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1
2019-02-04 CVE-2018-1801 XXE vulnerability in IBM products
IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 through V8.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
5.3
2019-01-30 CVE-2018-19858 XXE vulnerability in Princexml
PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities.
network
low complexity
princexml CWE-611
8.6
2019-01-18 CVE-2019-3774 XXE vulnerability in Pivotal Software Spring Batch
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
network
low complexity
pivotal-software CWE-611
critical
9.8
2019-01-18 CVE-2019-3773 XXE vulnerability in multiple products
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
network
low complexity
pivotal-software oracle CWE-611
critical
9.8
2019-01-18 CVE-2019-3772 XXE vulnerability in multiple products
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
network
low complexity
vmware oracle CWE-611
critical
9.8
2019-01-18 CVE-2018-20233 XXE vulnerability in Atlassian Universal Plugin Manager
The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privileges to read files, make network requests and perform a denial of service attack via an XML External Entity vulnerability in the parsing of atlassian plugin xml files in an uploaded JAR.
network
low complexity
atlassian CWE-611
6.5
2019-01-18 CVE-2018-2019 XXE vulnerability in IBM Security Identity Manager
IBM Security Identity Manager 6.0.0 Virtual Appliance is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1