Total
1209 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2020-36640 | 1 Bonitasoft | 1 Webservice Connector | 2024-11-21 | 4.9 MEDIUM | 5.5 MEDIUM |
|
A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function TransformerConfigurationException of the file src/main/java/org/bonitasoft/connectors/ws/SecureWSConnector.java. The manipulation leads to xml external entity reference. Upgrading to version 1.3.1 is able to address this issue. The patch is named a12ad691c05af19e9061d7949b6b828ce48815d5. It is recommended to upgrade the affected component. The associate ...
Show More |
|||||
| CVE-2020-36124 | 1 Paxtechnology | 1 Paxstore | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access tokens to access the platform as any desired user (clients and administrators).
|
|||||
| CVE-2020-35604 | 1 Kronos | 1 Web Time And Attendance | 2024-11-21 | 9.3 HIGH | 9.8 CRITICAL |
|
An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.
|
|||||
| CVE-2020-35123 | 1 Zimbra | 1 Collaboration | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra Collaboration Suite Network edition 9.0.0 Patch 10 and 8.8.15 Patch 17.
|
|||||
| CVE-2020-2324 | 1 Jenkins | 1 Cvs | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
|||||
| CVE-2020-2284 | 1 Jenkins | 1 Liquibase Runner | 2024-11-21 | 5.5 MEDIUM | 7.1 HIGH |
|
Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
|||||
| CVE-2020-2247 | 1 Jenkins | 1 Klocwork Analysis | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
|||||
| CVE-2020-2245 | 1 Jenkins | 1 Valgrind | 2024-11-21 | 5.5 MEDIUM | 7.1 HIGH |
|
Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
|||||
| CVE-2020-2178 | 1 Jenkins | 1 Parasoft Findings | 2024-11-21 | 5.5 MEDIUM | 7.1 HIGH |
|
Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
|||||
| CVE-2020-2171 | 1 Jenkins | 1 Rapiddeploy | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
|||||
| CVE-2020-2144 | 1 Jenkins | 1 Rundeck | 2024-11-21 | 5.5 MEDIUM | 7.1 HIGH |
|
Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
|||||
| CVE-2020-2138 | 1 Jenkins | 1 Cobertura | 2024-11-21 | 5.5 MEDIUM | 7.1 HIGH |
|
Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
|||||
| CVE-2020-2120 | 1 Jenkins | 1 Fitnesse | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
|
|||||
| CVE-2020-2115 | 1 Jenkins | 1 Nunit | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
|
|||||
| CVE-2020-2108 | 1 Jenkins | 1 Websphere Deployer | 2024-11-21 | 6.5 MEDIUM | 7.6 HIGH |
|
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Job/Configure permissions.
|
|||||
| CVE-2020-2092 | 1 Jenkins | 1 Robot Framework | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with Job/Configure to have Jenkins parse crafted XML documents.
|
|||||
| CVE-2020-2012 | 1 Paloaltonetworks | 1 Pan-os | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthenticated attackers with network access to the Panorama management interface to read arbitrary files on the system. This issue affects: All versions of PAN-OS for Panorama 7.1 and 8.0; PAN-OS for Panorama 8.1 versions earlier than 8.1.13; PAN-OS for Panorama 9.0 versions earlier than 9.0.7.
|
|||||
| CVE-2020-29436 | 1 Sonatype | 1 Nexus Repository Manager | 2024-11-21 | 5.5 MEDIUM | 6.5 MEDIUM |
|
Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.
|
|||||
| CVE-2020-28736 | 1 Plone | 1 Plone | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).
|
|||||
| CVE-2020-28734 | 1 Plone | 1 Plone | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
|
|||||
| CVE-2020-28387 | 1 Siemens | 1 Solid Edge | 2024-11-21 | 4.3 MEDIUM | 5.5 MEDIUM |
|
A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < SE2021MP3). When opening a specially crafted SEECTCXML file, the application could disclose arbitrary files to remote attackers. This is because of the passing of specially crafted content to the underlying XML parser without taking proper restrictions such as prohibiting an external dtd. (ZDI-CAN-11923)
|
|||||
| CVE-2020-27858 | 1 Arcserve | 1 D2d | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getNews method. Due to the improper restriction of XML External Entity (XXE) references, a specially-crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage ...
Show More |
|||||
| CVE-2020-27148 | 1 Tibco | 1 Ebx Add-ons | 2024-11-21 | 5.5 MEDIUM | 7.1 HIGH |
|
The TIBCO EBX Add-on for Oracle Hyperion EPM, TIBCO EBX Data Exchange Add-on, and TIBCO EBX Insight Add-on components of TIBCO Software Inc.'s TIBCO EBX Add-ons contain a vulnerability that theoretically allows a low privileged attacker with network access to execute an XML External Entity (XXE) attack. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.4.2 and below.
|
|||||
| CVE-2020-27017 | 2 Microsoft, Trendmicro | 2 Windows, Interscan Messaging Security Virtual Appliance | 2024-11-21 | 4.0 MEDIUM | 4.9 MEDIUM |
|
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must already have obtained product administrator/root privileges to exploit this vulnerability.
|
|||||
| CVE-2020-26981 | 1 Siemens | 2 Jt2go, Teamcenter Visualization | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). When opening a specially crafted xml file, the application could disclose arbitrary files to remote attackers. This is because of the passing of specially crafted content to the underlying XML parser without taking proper restrictions such as prohibiting an external dtd. (ZDI-CAN-11890)
|
|||||
| CVE-2020-26710 | 1 Easy-parse Project | 1 Easy-parse | 2024-11-21 | N/A | 7.5 HIGH |
|
easy-parse v0.1.1 was discovered to contain a XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.
|
|||||
| CVE-2020-26709 | 1 Py-xml Project | 1 Py-xml | 2024-11-21 | N/A | 7.5 HIGH |
|
py-xml v1.0 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.
|
|||||
| CVE-2020-26708 | 1 Requests-xml Project | 1 Requests-xml | 2024-11-21 | N/A | 7.5 HIGH |
|
requests-xml v0.2.3 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.
|
|||||
| CVE-2020-26705 | 1 Easyxml Project | 1 Easyxml | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
|
The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows for an attacker to expose sensitive data or perform a denial of service (DOS) via a crafted external entity entered into the XML content as input.
|
|||||
| CVE-2020-26564 | 1 Objectplanet | 1 Opinio | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file), and import this .xml file at the survey/admin/folderSurvey.do?action=viewImportSurvey['importFile'] URI. The XXE can then be triggered at a admin/preview.do?action=previewSurvey&surveyId= URI.
|
|||||
| CVE-2020-26513 | 1 Intland | 1 Codebeamer | 2024-11-21 | 4.3 MEDIUM | 5.5 MEDIUM |
|
An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM application to import projects, is parsed by insecurely configured software components, which can be abused for XML External Entity Attacks.
|
|||||
| CVE-2020-26247 | 2 Debian, Nokogiri | 2 Debian Linux, Nokogiri | 2024-11-21 | 4.0 MEDIUM | 2.6 LOW |
|
Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. Thi ...
Show More |
|||||
| CVE-2020-26229 | 1 Typo3 | 1 Typo3 | 2024-11-21 | 3.6 LOW | 3.7 LOW |
|
TYPO3 is an open source PHP based web content management system. In TYPO3 from version 10.4.0, and before version 10.4.10, RSS widgets are susceptible to XML external entity processing. This vulnerability is reasonable, but is theoretical - it was not possible to actually reproduce the vulnerability with current PHP versions of supported and maintained system distributions. At least with libxml2 version 2.9, the processing of XML external entities is disabled per default - and cannot be exploite ...
Show More |
|||||
| CVE-2020-26064 | 1 Cisco | 1 Catalyst Sd-wan Manager | 2024-11-21 | N/A | 8.1 HIGH |
|
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system.
The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by persuading a user to import a crafted XML file with malicious entries. A successful exploit could allow the attacker to read and write files wi ...
Show More |
|||||
| CVE-2020-25912 | 1 Getsymphony | 1 Symphony | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
|
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
|
|||||
| CVE-2020-25911 | 1 Modx | 1 Modx Revolution | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
|
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
|
|||||
| CVE-2020-25817 | 1 Silverstripe | 1 Silverstripe | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utility is misused for purposes involving external or user submitted data in custom project code, it can lead to vulnerabilities such as XSS on HTML output rendered through this custom code. This is now mitigated by disabling external entities during parsing. (The correct CVE ID year i ...
Show More |
|||||
| CVE-2020-25750 | 1 Dotplant | 1 Dotplant2 | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']) is used for simplexml_load_string without sanitization. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
|
|||||
| CVE-2020-25649 | 6 Apache, Fasterxml, Fedoraproject and 3 more | 39 Iotdb, Jackson-databind, Fedora and 36 more | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
|
|||||
| CVE-2020-25257 | 1 Hyland | 1 Onbase | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows XXE attacks for read/write access to arbitrary files.
|
|||||