Vulnerability index

Browse CVEs

127 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
MEDIUM 6.5 CVE-2026-18715 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external e… I No fix yet Fix from $4,0002026-08-13 CRITICAL 9.8 CVE-2026-10025 IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulne… Qradar Security Information And Event Manager No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-13449 IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML … Business Automation Manager 9.5.0+ Fix from $2,3002026-06-30 HIGH 7.1 CVE-2026-3603 IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7… Engineering Lifecycle Management Patch available Fix from $1,9502026-05-26 HIGH 7.5 CVE-2026-1567 IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could all… Infosphere Information Server after 11.7.1.6 Fix from $1,9502026-03-03 HIGH 8.2 CVE-2025-36247 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external en… Db2 after 12.1.3 Fix from $1,9502026-02-17 CRITICAL 9.1 CVE-2025-12531 IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. … Infosphere Information Server after 11.7.1.6 Fix from $2,3002025-11-03 HIGH 7.1 CVE-2025-33121 IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remot… Qradar Security Information And Event Manager Mitigation only Fix from $1,9502025-06-19 HIGH 8.8 CVE-2025-36049 IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML d… Webmethods Integration Mitigation only Fix from $1,9502025-06-18 HIGH 7.1 CVE-2025-0162 IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenti… Aspera Shares 1.10.0+ Fix from $1,9502025-03-07 HIGH 7.1 CVE-2024-49781 IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote… Openpages With Watson 8.3.0.3 / 9.0.0.5+ Fix from $1,9502025-02-20 HIGH 8.2 CVE-2023-47160 IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when p… Cognos Controller 11.0.1.4+ Fix from $1,9502025-02-19 HIGH 7.1 CVE-2024-54171 IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit thi… Entirex Mitigation only Fix from $1,9502025-02-06 HIGH 7.1 CVE-2024-49352 IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injec… Cognos Analytics 11.2.4 / 12.0.4+ Fix from $1,9502025-02-05 HIGH 8.2 CVE-2024-39726 IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when pro… Engineering Lifecycle Optimization Engineering Insights Mitigation only Fix from $1,9502024-11-15 MEDIUM 5.5 CVE-2024-45086 IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged us… Websphere Application Server 8.5.5.27 / 9.0.5.22+ Fix from $1,6002024-11-04 MEDIUM 5.5 CVE-2024-45072 IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged us… Websphere Application Server after 9.0.5.21 Fix from $1,6002024-10-16 HIGH 8.2 CVE-2023-50304 IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML d… Engineering Requirements Management Doors Mitigation only Fix from $1,9502024-07-18 HIGH 8.2 CVE-2023-45192 IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML… Doors Next Mitigation only Fix from $1,9502024-06-06 HIGH 7.0 CVE-2024-22354 IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External En… Websphere Application Server 8.5.5.26 / 9.0.5.20+ Fix from $1,9502024-04-17 HIGH 8.2 CVE-2024-27266 IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could… Maximo Application Suite Patch available Fix from $1,9502024-03-14 HIGH 8.2 CVE-2023-25926 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when proce… Security Guardium Key Lifecycle Manager 4.1.1.7+ Fix from $1,9502024-02-29 HIGH 7.1 CVE-2023-32327 IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 … Security Verify Access after 10.0.6.1 Fix from $1,9502024-02-03 CRITICAL 9.1 CVE-2022-32755 IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could … Security Directory Server Patch available Fix from $2,3002023-10-14 CRITICAL 9.1 CVE-2023-35892 IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A… Financial Transaction Manager Mitigation only Fix from $2,3002023-09-05 MEDIUM 6.3 CVE-2023-27554 IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attack… Websphere Application Server 8.5.5.24 / 9.0.5.16+ Fix from $1,6002023-05-11 HIGH 7.1 CVE-2023-27876 IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnera… Tririga Application Platform Patch available Fix from $1,9502023-04-07 HIGH 8.8 CVE-2023-27874 IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker coul… Aspera Faspex after 4.4.2 Fix from $1,9502023-03-21 CRITICAL 9.1 CVE-2022-38389 IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at… Tivoli Workload Scheduler Mitigation only Fix from $2,3002023-02-03 CRITICAL 9.1 CVE-2022-22486 IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at… Tivoli Workload Scheduler Mitigation only Fix from $2,3002023-02-03