Vulnerability index

Browse CVEs

127 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
I MEDIUM 6.5
CVE-2026-18715

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external e…

No fix yet
Fix from $4,000 2026-08-13
Qradar Security Information And Event Manager CRITICAL 9.8
CVE-2026-10025

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulne…

No fix yet
Fix from $2,300 2026-08-05
Business Automation Manager CRITICAL 9.1
CVE-2026-13449

IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML …

Fix: 9.5.0+
Fix from $2,300 2026-06-30
Engineering Lifecycle Management HIGH 7.1
CVE-2026-3603

IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7…

Patch available
Fix from $1,950 2026-05-26
Infosphere Information Server HIGH 7.5
CVE-2026-1567

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could all…

Fix: after 11.7.1.6
Fix from $1,950 2026-03-03
Db2 HIGH 8.2
CVE-2025-36247

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external en…

Fix: after 12.1.3
Fix from $1,950 2026-02-17
Infosphere Information Server CRITICAL 9.1
CVE-2025-12531

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. …

Fix: after 11.7.1.6
Fix from $2,300 2025-11-03
Qradar Security Information And Event Manager HIGH 7.1
CVE-2025-33121

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remot…

Mitigation only
Fix from $1,950 2025-06-19
Webmethods Integration HIGH 8.8
CVE-2025-36049

IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML d…

Mitigation only
Fix from $1,950 2025-06-18
Aspera Shares HIGH 7.1
CVE-2025-0162

IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenti…

Fix: 1.10.0+
Fix from $1,950 2025-03-07
Openpages With Watson HIGH 7.1
CVE-2024-49781

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote…

Fix: 8.3.0.3 / 9.0.0.5+
Fix from $1,950 2025-02-20
Cognos Controller HIGH 8.2
CVE-2023-47160

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when p…

Fix: 11.0.1.4+
Fix from $1,950 2025-02-19
Entirex HIGH 7.1
CVE-2024-54171

IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit thi…

Mitigation only
Fix from $1,950 2025-02-06
Cognos Analytics HIGH 7.1
CVE-2024-49352

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injec…

Fix: 11.2.4 / 12.0.4+
Fix from $1,950 2025-02-05
Engineering Lifecycle Optimization Engineering Insights HIGH 8.2
CVE-2024-39726

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when pro…

Mitigation only
Fix from $1,950 2024-11-15
Websphere Application Server MEDIUM 5.5
CVE-2024-45086

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged us…

Fix: 8.5.5.27 / 9.0.5.22+
Fix from $1,600 2024-11-04
Websphere Application Server MEDIUM 5.5
CVE-2024-45072

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged us…

Fix: after 9.0.5.21
Fix from $1,600 2024-10-16
Engineering Requirements Management Doors HIGH 8.2
CVE-2023-50304

IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML d…

Mitigation only
Fix from $1,950 2024-07-18
Doors Next HIGH 8.2
CVE-2023-45192

IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML…

Mitigation only
Fix from $1,950 2024-06-06
Websphere Application Server HIGH 7.0
CVE-2024-22354

IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External En…

Fix: 8.5.5.26 / 9.0.5.20+
Fix from $1,950 2024-04-17
Maximo Application Suite HIGH 8.2
CVE-2024-27266

IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could…

Patch available
Fix from $1,950 2024-03-14
Security Guardium Key Lifecycle Manager HIGH 8.2
CVE-2023-25926

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when proce…

Fix: 4.1.1.7+
Fix from $1,950 2024-02-29
Security Verify Access HIGH 7.1
CVE-2023-32327

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …

Fix: after 10.0.6.1
Fix from $1,950 2024-02-03
Security Directory Server CRITICAL 9.1
CVE-2022-32755

IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could …

Patch available
Fix from $2,300 2023-10-14
Financial Transaction Manager CRITICAL 9.1
CVE-2023-35892

IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A…

Mitigation only
Fix from $2,300 2023-09-05
Websphere Application Server MEDIUM 6.3
CVE-2023-27554

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attack…

Fix: 8.5.5.24 / 9.0.5.16+
Fix from $1,600 2023-05-11
Tririga Application Platform HIGH 7.1
CVE-2023-27876

IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnera…

Patch available
Fix from $1,950 2023-04-07
Aspera Faspex HIGH 8.8
CVE-2023-27874

IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker coul…

Fix: after 4.4.2
Fix from $1,950 2023-03-21
Tivoli Workload Scheduler CRITICAL 9.1
CVE-2022-38389

IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Mitigation only
Fix from $2,300 2023-02-03
Tivoli Workload Scheduler CRITICAL 9.1
CVE-2022-22486

IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Mitigation only
Fix from $2,300 2023-02-03