Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2018-03-12 CVE-2016-0250 XXE vulnerability in IBM Infosphere Information Server 11.3/11.3.1/11.5
XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote authenticated users to read arbitrary files or cause a denial of service via crafted XML data.
network
low complexity
ibm CWE-611
5.5
2018-03-09 CVE-2018-7230 XXE vulnerability in Schneider-Electric products
A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67.
6.8
2018-03-09 CVE-2016-0268 XXE vulnerability in IBM Financial Transaction Manager
XML external entity (XXE) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote authenticated users to obtain sensitive information via crafted XML data.
network
low complexity
ibm CWE-611
4.0
2018-03-08 CVE-2018-0218 XXE vulnerability in Cisco Secure Access Control Server Solution Engine 5.8(0.8)
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system.
network
cisco CWE-611
4.3
2018-03-08 CVE-2018-0207 XXE vulnerability in Cisco Secure Access Control Server Solution Engine 5.8(0.8)
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system.
network
cisco CWE-611
4.3
2018-03-01 CVE-2017-7426 XXE vulnerability in Netiq Identity Manager 4.5/4.6
The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to leak information or cause denial of service attacks.
network
low complexity
netiq CWE-611
critical
9.1
2018-02-24 CVE-2017-18197 XXE vulnerability in Jgraph Mxgraph
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
network
low complexity
jgraph CWE-611
7.5
2018-02-22 CVE-2018-6489 XXE vulnerability in Microfocus Project and Portfolio Management Center 9.32
XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32.
network
low complexity
microfocus CWE-611
critical
9.8
2018-02-21 CVE-2017-1758 XXE vulnerability in IBM products
IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
5.5
2018-02-21 CVE-2016-0369 XXE vulnerability in IBM Forms Experience Builder 8.5/8.5.1/8.6.0
XML external entity (XXE) vulnerability in IBM Forms Experience Builder 8.5, 8.5.1, and 8.6 allows remote authenticated users to obtain sensitive information via crafted XML data.
network
low complexity
ibm CWE-611
4.0