Vulnerability index

Browse CVEs

70 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Log4net CRITICAL 9.8
CVE-2018-1285EPSS 17%

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attack…

Fix: 2.0.10+
Fix from $2,300 2020-05-11
Olingo MEDIUM 5.5
CVE-2019-17554EPSS 12%

The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Requ…

Fix: after 4.6.0
Fix from $1,600 2019-12-04
Ofbiz HIGH 7.5
CVE-2011-3600EPSS 16%

The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with exe…

Fix: after 16.11.04
Fix from $1,950 2019-11-26
Nifi MEDIUM 6.5
CVE-2019-10080

The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML f…

Fix: after 1.9.2
Fix from $1,600 2019-11-19
Poi MEDIUM 5.5
CVE-2019-12415

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can a…

Fix: after 4.1.0
Fix from $1,600 2019-10-23
Tomee CRITICAL 9.8
CVE-2019-13990EPSS 16%

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

Fix: 2.3.2+
Fix from $2,300 2019-07-26
Camel HIGH 7.5
CVE-2019-0188EPSS 10%

Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib lib…

Fix: 2.24.0+
Fix from $1,950 2019-05-28
Pdfbox CRITICAL 9.8
CVE-2019-0228EPSS 9%

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attac…

Mitigation only
Fix from $2,300 2019-04-17
Karaf CRITICAL 9.8
CVE-2018-11788EPSS 7%

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The …

Fix: 4.1.7+
Fix from $2,300 2019-01-07
Syncope HIGH 7.2
CVE-2018-17186

An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file writ…

Fix: after 2.1.2
Fix from $1,950 2018-11-06
Tika HIGH 7.5
CVE-2018-11796EPSS 7%

In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after eac…

Fix: after 1.19
Fix from $1,950 2018-10-09
Tika HIGH 7.5
CVE-2018-11761EPSS 10%

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vuln…

Fix: after 1.18
Fix from $1,950 2018-09-19
Cayenne HIGH 8.1
CVE-2018-11758

This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler is a desktop GUI tool shippe…

Fix: after 3.1.0
Fix from $1,950 2018-08-22
Camel CRITICAL 9.8
CVE-2018-8027EPSS 6%

Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.

Fix: after 2.20.3
Fix from $2,300 2018-07-31
Solr MEDIUM 5.5
CVE-2018-8026EPSS 9%

This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.…

Fix: after 7.3.1
Fix from $1,600 2018-07-05
Nifi CRITICAL 9.8
CVE-2018-1309

Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The f…

Fix: 1.6.0+
Fix from $2,300 2018-05-23
Solr MEDIUM 5.5
CVE-2018-8010

This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.x…

Fix: after 7.3.0
Fix from $1,600 2018-05-21
Uimaj MEDIUM 6.5
CVE-2017-15691EPSS 9%

In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, Apache ui…

Fix: 2.2.2 / 2.4.0+
Fix from $1,600 2018-04-26
Solr HIGH 7.5
CVE-2018-1308EPSS 21%

This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` …

Fix: after 7.2.1
Fix from $1,950 2018-04-09
Juddi HIGH 8.1
CVE-2018-1307

In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data…

Fix: after 3.3.4
Fix from $1,950 2018-02-09
Solr CRITICAL 9.1
CVE-2017-1000190

SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.

Fix: after 2.7.1
Fix from $2,300 2017-11-17
Activemq Apollo CRITICAL 9.8
CVE-2014-3579

XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors inv…

Mitigation only
Fix from $2,300 2017-10-27
Activemq CRITICAL 9.8
CVE-2014-3600EPSS 10%

XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving…

Mitigation only
Fix from $2,300 2017-10-27
Xml Rpc HIGH 7.8
CVE-2016-5002EPSS 8%

XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to co…

Mitigation only
Fix from $1,950 2017-10-27
Solr CRITICAL 9.8
CVE-2017-12629EPSS 92%

Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-li…

Fix: after 7.0.1
Fix from $2,300 2017-10-14
Nifi MEDIUM 6.5
CVE-2017-12623

An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The f…

Mitigation only
Fix from $1,600 2017-10-10
Roller CRITICAL 9.8
CVE-2014-0030EPSS 17%

The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.

No fix yet
Fix from $2,300 2017-10-10
Opennlp CRITICAL 9.8
CVE-2017-12620

When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects ap…

No fix yet
Fix from $2,300 2017-10-03
Tika HIGH 7.8
CVE-2016-4434

Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External En…

Mitigation only
Fix from $1,950 2017-09-30
Commons Jelly CRITICAL 9.8
CVE-2017-12621EPSS 9%

During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used …

Fix: 1.0.1+
Fix from $2,300 2017-09-28