Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2018-03-12 CVE-2018-5758 XXE vulnerability in Aurea Jive-N 9.0.2.1
The Upload File functionality in upload.jspa in Aurea Jive Jive-n 9.0.2.1 On-Premises allows for an XML External Entity attack through a crafted file, allowing attackers to read arbitrary files.
network
low complexity
aurea CWE-611
6.5
2018-03-12 CVE-2016-0250 XXE vulnerability in IBM Infosphere Information Server
XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote authenticated users to read arbitrary files or cause a denial of service via crafted XML data.
network
low complexity
ibm CWE-611
5.4
2018-03-09 CVE-2018-7230 XXE vulnerability in Schneider-Electric products
A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67.
network
low complexity
schneider-electric CWE-611
8.8
2018-03-09 CVE-2016-0268 XXE vulnerability in IBM Financial Transaction Manager
XML external entity (XXE) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote authenticated users to obtain sensitive information via crafted XML data.
network
low complexity
ibm CWE-611
4.3
2018-03-08 CVE-2018-0218 XXE vulnerability in Cisco Secure Access Control Server Solution Engine 5.8(0.8)
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system.
local
low complexity
cisco CWE-611
3.3
2018-03-08 CVE-2018-0207 XXE vulnerability in Cisco Secure Access Control Server Solution Engine 5.8(0.8)
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system.
local
low complexity
cisco CWE-611
3.3
2018-03-01 CVE-2017-7426 XXE vulnerability in Netiq Identity Manager 4.5/4.6
The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to leak information or cause denial of service attacks.
network
low complexity
netiq CWE-611
critical
9.1
2018-02-24 CVE-2017-18197 XXE vulnerability in Jgraph Mxgraph
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
network
low complexity
jgraph CWE-611
critical
9.8
2018-02-22 CVE-2018-6489 XXE vulnerability in Microfocus Project and Portfolio Management Center 9.32
XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32.
network
low complexity
microfocus CWE-611
critical
9.8
2018-02-21 CVE-2017-1758 XXE vulnerability in IBM products
IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1