Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Sterling B2b Integrator HIGH 8.2
CVE-2017-1192

IBM Sterling B2B Integrator 5.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could expl…

Mitigation only
Fix from $1,950 2017-08-10
Wink HIGH 7.4
CVE-2010-2245EPSS 12%

XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service…

Fix: after 1.1.1
Fix from $1,950 2017-08-08
Control Manager HIGH 7.5
CVE-2017-11390

XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly Z…

Patch available
Fix from $1,950 2017-08-02
Sterling B2b Integrator MEDIUM 6.5
CVE-2015-0194

XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers …

Patch available
Fix from $1,600 2017-08-02
Infosphere Information Server CRITICAL 9.1
CVE-2017-1383

IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remot…

Mitigation only
Fix from $2,300 2017-08-02
Python HIGH 7.5
CVE-2017-9233EPSS 9%

XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop usi…

Fix: 2.7.15 / 3.3.7+
Fix from $1,950 2017-07-25
Netweaver Application Server Java MEDIUM 6.5
CVE-2017-11457

XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files o…

Mitigation only
Fix from $1,600 2017-07-25
Bigfix Platform MEDIUM 6.5
CVE-2017-1219

IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit t…

Mitigation only
Fix from $1,600 2017-07-19
Sling CRITICAL 9.8
CVE-2016-6798

In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string…

Fix: after 1.0.10
Fix from $2,300 2017-07-19
Openmeetings CRITICAL 10.0
CVE-2017-7664

Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.

Mitigation only
Fix from $2,300 2017-07-17
Xmlsec HIGH 7.1
CVE-2017-1000061

xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information discl…

Fix: after 1.2.23
Fix from $1,950 2017-07-17
Logicaldoc HIGH 8.8
CVE-2017-1000021

LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.

Fix: after 7.5.3
Fix from $1,950 2017-07-17
Windows 10 MEDIUM 6.5
CVE-2017-0170EPSS 7%

Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windo…

Patch available
Fix from $1,600 2017-07-11
Windows 10 MEDIUM 5.5
CVE-2017-8557

Windows System Information Console in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1…

Patch available
Fix from $1,600 2017-07-11
Security Guardium HIGH 7.1
CVE-2017-1254

IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit th…

Mitigation only
Fix from $1,950 2017-07-05
Osci Transport Library CRITICAL 9.8
CVE-2017-10670

An XML External Entity (XXE) issue exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET),…

Mitigation only
Fix from $2,300 2017-06-30
Api Connect HIGH 8.2
CVE-2017-1322

IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this…

Patch available
Fix from $1,950 2017-06-27
Evolved Programmable Network Manager HIGH 8.0
CVE-2017-6662

A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an aut…

Mitigation only
Fix from $1,950 2017-06-26
Xenmobile Server HIGH 7.5
CVE-2017-9231

XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via …

Mitigation only
Fix from $1,950 2017-06-16
Rational Rhapsody Design Manager HIGH 8.1
CVE-2016-9698

IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML da…

Patch available
Fix from $1,950 2017-06-08
Cognos Business Intelligence MEDIUM 6.5
CVE-2016-0254

IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when proc…

Patch available
Fix from $1,600 2017-06-07
Webdav CRITICAL 9.8
CVE-2015-7326

XML External Entity (XXE) vulnerability in Milton Webdav before 2.7.0.3.

Fix: after 2.7.0.1
Fix from $2,300 2017-06-07
Junos Space MEDIUM 6.5
CVE-2017-2308

An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbit…

Fix: after 16.1
Fix from $1,600 2017-05-30
Device Manager MEDIUM 6.5
CVE-2017-9295

XXE vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to read…

Fix: after 8.5.2
Fix from $1,600 2017-05-29
Business One CRITICAL 9.6
CVE-2016-6256EPSS 8%

SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcell…

No fix yet
Fix from $2,300 2017-05-26
Spring Framework HIGH 8.8
CVE-2014-0225

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not d…

Mitigation only
Fix from $1,950 2017-05-25
Netweaver Application Server Java HIGH 8.8
CVE-2017-8913

The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks…

Mitigation only
Fix from $1,950 2017-05-23
Sdk HIGH 8.2
CVE-2017-1289

IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit th…

Fix: after 8
Fix from $1,950 2017-05-22
Wonderware Historian Client MEDIUM 6.6
CVE-2017-7907

An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 and prior. An improperly rest…

Fix: after 2014_r2
Fix from $1,600 2017-05-19
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7503

It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use th…

Mitigation only
Fix from $2,300 2017-05-18