Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2019-02-04 CVE-2018-1970 XXE vulnerability in IBM Security Access Manager
IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1
2019-02-04 CVE-2018-1801 XXE vulnerability in IBM products
IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 through V8.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
5.3
2019-01-30 CVE-2018-19858 XXE vulnerability in Princexml
PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities.
network
low complexity
princexml CWE-611
8.6
2019-01-18 CVE-2019-3774 XXE vulnerability in Pivotal Software Spring Batch
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
network
low complexity
pivotal-software CWE-611
critical
9.8
2019-01-18 CVE-2019-3773 XXE vulnerability in multiple products
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
network
low complexity
pivotal-software oracle CWE-611
critical
9.8
2019-01-18 CVE-2019-3772 XXE vulnerability in multiple products
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
network
low complexity
vmware oracle CWE-611
critical
9.8
2019-01-18 CVE-2018-20233 XXE vulnerability in Atlassian Universal Plugin Manager
The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privileges to read files, make network requests and perform a denial of service attack via an XML External Entity vulnerability in the parsing of atlassian plugin xml files in an uploaded JAR.
network
low complexity
atlassian CWE-611
6.5
2019-01-18 CVE-2018-2019 XXE vulnerability in IBM Security Identity Manager
IBM Security Identity Manager 6.0.0 Virtual Appliance is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1
2019-01-17 CVE-2018-20733 XXE vulnerability in SAS web Infrastructure Platform 9.4
BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.
network
low complexity
sas CWE-611
7.5
2019-01-16 CVE-2015-9280 XXE vulnerability in Mailenable
MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.
network
low complexity
mailenable CWE-611
critical
10.0