IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attack
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processi
The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenTex
IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attac
An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker t
SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6
Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when
php-saml-sp before 1.1.1 and 2.x before 2.1.1 allows reading arbitrary files as the webserver user because resolving XML
GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. Geo
Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entit
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. In
An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input va
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remot
Jenkins External Monitor Job Type Plugin 206.v9a_94ff0b_4a_10 and earlier does not configure its XML parser to prevent X
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Eclipse Leshan is a device management server and client Java implementation. In affected versions DDFFileParser` and `De
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters
An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component.
A vulnerability was found in zwczou WeChat SDK Python 0.3.0 and classified as critical. This issue affects the function
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when proces
The Foundry Magritte plugin rest-source was found to be vulnerable to an an XML external Entity attack (XXE).
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in
A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Enti
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.
Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client DICOM RTst Loading modul
A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. T
A vulnerability classified as problematic was found in gturri aXMLRPC up to 1.12.0. This vulnerability affects the funct
A vulnerability classified as problematic was found in e-Contract dssp up to 1.3.1. Affected by this vulnerability is th
A vulnerability classified as problematic was found in kelvinmo simplexrd up to 3.1.0. This vulnerability affects unknow
A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown co
Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and ea
A vulnerability was found in java-xmlbuilder up to 1.1. It has been rated as problematic. Affected by this issue is some
A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_x
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft
National land numerical information data conversion tool all versions improperly restricts XML external entity reference
All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks
All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks
An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of serv
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft
A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the
Improper restriction of XML external entity reference (XXE) vulnerability exists in FRENIC RHC Loader v1.1.0.3 and earli
A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this is
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause loss of confiden
Frequently Asked Questions
What is CWE-611?
CWE-611 (CWE-611) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-611?
There are 1,556 CVE records associated with CWE-611 in our database. Of these, 259 are critical severity, 556 are high severity, and 397 are medium severity.
How can I protect against CWE-611 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-611 using AI-powered security agents.
Detect CWE-611 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-611 vulnerabilities across your infrastructure.
Get Started