Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2018-02-21 CVE-2016-0369 XXE vulnerability in IBM Forms Experience Builder 8.5/8.5.1/8.6.0
XML external entity (XXE) vulnerability in IBM Forms Experience Builder 8.5, 8.5.1, and 8.6 allows remote authenticated users to obtain sensitive information via crafted XML data.
network
low complexity
ibm CWE-611
2.7
2018-02-19 CVE-2017-7375 XXE vulnerability in multiple products
A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes).
network
low complexity
xmlsoft debian google CWE-611
critical
9.8
2018-02-15 CVE-2017-5828 XXE vulnerability in HP Aruba Clearpass Policy Manager
An arbitrary command execution vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.
network
low complexity
hp CWE-611
8.1
2018-02-14 CVE-2018-2393 XXE vulnerability in SAP Internet Graphics Server
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
network
low complexity
sap CWE-611
7.5
2018-02-14 CVE-2018-2392 XXE vulnerability in SAP Internet Graphics Server
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
network
low complexity
sap CWE-611
7.5
2018-02-09 CVE-2018-3600 XXE vulnerability in Trendmicro Control Manager 6.0
A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to disclose sensitive information on vulnerable installations.
network
low complexity
trendmicro CWE-611
6.5
2018-02-09 CVE-2018-1307 XXE vulnerability in Apache Juddi
In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data structures into UDDI data structures, there are little protections present against entity expansion and DTD type of attacks.
network
high complexity
apache CWE-611
8.1
2018-02-05 CVE-2018-5789 XXE vulnerability in Extremewireless Wing
An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3.
network
low complexity
extremewireless CWE-611
7.5
2018-02-02 CVE-2018-6486 XXE vulnerability in Microfocus products
XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), versions 16.10, 16.20, 17.10.
network
low complexity
microfocus CWE-611
critical
9.8
2018-02-01 CVE-2014-3244 XXE vulnerability in Sugarcrm
XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.
network
low complexity
sugarcrm CWE-611
critical
9.8