Vulnerability index

Browse CVEs

12 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Build Of Apicurio Registry HIGH 8.5
CVE-2026-12975

A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing featu…

Fix: after 3.2
Fix from $1,950 2026-06-25
Jboss A Mq MEDIUM 5.6
CVE-2020-14379

A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and info…

Mitigation only
Fix from $1,600 2022-08-16
Process Automation Manager HIGH 8.2
CVE-2022-2458

XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application's processing of XML data. This attack …

Fix: 7.13.1+
Fix from $1,950 2022-08-10
Drools CRITICAL 9.8
CVE-2021-41411

drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, res…

Fix: 7.6.0+
Fix from $2,300 2022-06-16
Spacewalk CRITICAL 9.8
CVE-2020-1693

A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated …

Fix: 2.9+
Fix from $2,300 2020-02-17
Jboss Enterprise Application Platform HIGH 7.5
CVE-2019-10172EPSS 17%

A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects c…

Fix: after 1.9.13
Fix from $1,950 2019-11-18
Hornetq MEDIUM 6.5
CVE-2014-3599

HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy

Fix: after 2.4.5
Fix from $1,600 2019-11-12
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7464

It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use thi…

Mitigation only
Fix from $2,300 2018-07-27
Decision Manager MEDIUM 6.5
CVE-2017-7545

It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote a…

Patch available
Fix from $1,600 2018-07-26
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7465

It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw …

Mitigation only
Fix from $2,300 2018-06-27
Spacewalk HIGH 7.5
CVE-2018-1077

Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.

Mitigation only
Fix from $1,950 2018-03-14
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7503

It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use th…

Mitigation only
Fix from $2,300 2017-05-18