Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-09-05 | CVE-2023-35892 | XXE vulnerability in IBM Financial Transaction Manager 3.2.4 IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. | 9.1 |
2023-09-01 | CVE-2023-40239 | XXE vulnerability in Lexmark products Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. | 7.5 |
2023-08-31 | CVE-2023-41034 | XXE vulnerability in Eclipse Leshan Eclipse Leshan is a device management server and client Java implementation. | 9.8 |
2023-08-25 | CVE-2023-24620 | XXE vulnerability in Esotericsoftware Yamlbeans An issue was discovered in Esoteric YamlBeans through 1.15. | 5.5 |
2023-08-22 | CVE-2022-48565 | XXE vulnerability in multiple products An XML External Entity (XXE) issue was discovered in Python through 3.9.1. | 9.8 |
2023-08-21 | CVE-2022-46751 | XXE vulnerability in Apache IVY Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2. When Apache Ivy prior to 2.5.2 parses XML files - either its own configuration, Ivy files or Apache Maven POMs - it will allow downloading external document type definitions and expand any entity references contained therein when used. This can be used to exfiltrate data, access resources only the machine running Ivy has access to or disturb the execution of Ivy in different ways. Starting with Ivy 2.5.2 DTD processing is disabled by default except when parsing Maven POMs where the default is to allow DTD processing but only to include a DTD snippet shipping with Ivy that is needed to deal with existing Maven POMs that are not valid XML files but are nevertheless accepted by Maven. | 8.2 |
2023-08-11 | CVE-2023-0871 | XXE vulnerability in Opennms Horizon and Meridian XXE injection in /rtc/post/ endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to XML external entity (XXE) injection, which can be used for instance to force Horizon to make arbitrary HTTP requests to internal and external services. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. | 6.1 |
2023-08-11 | CVE-2023-3823 | XXE vulnerability in multiple products In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. | 7.5 |
2023-08-10 | CVE-2023-32567 | XXE vulnerability in Ivanti Avalanche Ivanti Avalanche decodeToMap XML External Entity Processing. | 9.8 |
2023-08-04 | CVE-2020-26064 | XXE vulnerability in Cisco Catalyst Sd-Wan Manager A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. | 8.1 |