Vulnerabilities (CVE)

Filtered by CWE-611
Total 1093 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-1077 1 Redhat 2 Satellite, Spacewalk 2024-11-21 5.0 MEDIUM 7.5 HIGH
Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.
CVE-2018-19858 1 Princexml 1 Princexml 2024-11-21 5.0 MEDIUM 8.6 HIGH
PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an attacker passes HTML referencing an XML file (e.g., in an IFRAME element), PrinceXML will fetch the XML and parse it, thus giving an attacker file-read access and full-fledged SSRF.
CVE-2018-19371 1 Sdl 1 Web Content Manager 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.
CVE-2018-19244 1 Charlesproxy 1 Charles 2024-11-21 5.0 MEDIUM 8.6 HIGH
An XML External Entity (XXE) vulnerability exists in the Charles 4.2.7 import/export setup option. If a user imports a "Charles Settings.xml" file from an attacker, an intranet network may be accessed and information may be leaked.
CVE-2018-18980 1 Zohocorp 2 Manageengine Network Configuration Manager, Manageengine Opmanager 2024-11-21 5.0 MEDIUM 7.5 HIGH
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.
CVE-2018-18737 1 Douchat 1 Douchat 2024-11-21 5.0 MEDIUM 7.5 HIGH
An XXE issue was discovered in Douchat 4.0.4 because Data\notify.php calls simplexml_load_string. This can also be used for SSRF.
CVE-2018-18659 1 Arcserve 1 Udp 2024-11-21 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-19 Unauthenticated XXE in /management/UdpHttpService issue.
CVE-2018-18471 4 Axentra, Medion, Netgear and 1 more 4 Hipserv, Lifecloud, Stora and 1 more 2024-11-21 10.0 HIGH 9.8 CRITICAL
/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can be chained with an SSRF bug to gain remote command execution as root. It can be triggered by anyone who knows the IP address of the affected device.
CVE-2018-18406 1 Tufin 2 Securetrack, Tufinos 2024-11-21 6.5 MEDIUM 9.9 CRITICAL
An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE vulnerability when a new Best Practices Report is saved using a special payload inside the xml input field. The XXE vulnerability is blind since the response doesn't directly display a requested file, but rather returns it inside the name data field when the report is saved. An attacker is able to view restricted operating system files. This issue affects all types of users: administrators or normal users.
CVE-2018-17912 1 Sauter-controls 1 Case Suite 2024-11-21 5.0 MEDIUM 7.5 HIGH
An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow remote file disclosure.
CVE-2018-17889 1 We-con 2 Pi Studio, Pi Studio Hmi 2024-11-21 4.3 MEDIUM 5.3 MEDIUM
In WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior when parsing project files, the XMLParser that ships with Wecon PIStudio is vulnerable to a XML external entity injection attack, which may allow sensitive information disclosure.
CVE-2018-17411 1 Informationbuilders 1 Data Quality Suite 2024-11-21 10.0 HIGH 9.8 CRITICAL
An XML External Entity (XXE) vulnerability exists in iWay Data Quality Suite Web Console 10.6.1.ga-2016-11-20.
CVE-2018-17289 1 Kofax 1 Front Office Server 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
An XML external entity (XXE) vulnerability in Kofax Front Office Server Administration Console version 4.1.1.11.0.5212 allows remote authenticated users to read arbitrary files via crafted XML inside an imported package configuration (.ZIP file) within the Kofax/KFS/Admin/PackageService/package/upload file parameter.
CVE-2018-17247 1 Elastic 1 Elasticsearch 2024-11-21 4.3 MEDIUM 5.9 MEDIUM
Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a specially crafted request capable of leaking content of local files on the Elasticsearch node. This could allow a user to access information that they should not have access to.
CVE-2018-17186 1 Apache 1 Syncope 2024-11-21 6.5 MEDIUM 7.2 HIGH
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
CVE-2018-17169 1 Printeron 1 Printeron 2024-11-21 4.0 MEDIUM 7.7 HIGH
An XML external entity (XXE) vulnerability in PrinterOn version 4.1.4 and lower allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
CVE-2018-17152 1 Intersystems 1 Cache 2024-11-21 5.5 MEDIUM 6.4 MEDIUM
Intersystems Cache 2017.2.2.865.0 allows XXE.
CVE-2018-16792 1 Solarwinds 1 Sftp\/scp Server 2024-11-21 6.4 MEDIUM 9.1 CRITICAL
SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.
CVE-2018-16521 1 Openmrs 2 Html Form Entry, Reference Application 2024-11-21 7.5 HIGH 9.8 CRITICAL
An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0.
CVE-2018-16252 1 Fspro 1 Event Log Explorer 2024-11-21 2.1 LOW 3.3 LOW
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.