目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-611 XML外部实体引用的不恰当限制(XXE) 类漏洞列表 482

CWE-611 XML外部实体引用的不恰当限制(XXE) 类弱点 482 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-611 指 XML 外部实体注入漏洞,属于处理 XML 文档时的安全缺陷。攻击者通过构造包含恶意外部实体的 XML 数据,诱导系统读取服务器本地文件或发起 SSRF 请求,从而泄露敏感信息或探测内网。开发者应避免使用默认配置解析 XML,禁用外部实体解析功能,并对输入数据进行严格校验与过滤,确保仅处理受信任的实体引用。

MITRE CWE 官方描述
CWE:CWE-611 XML外部实体引用限制不当 英文:该产品处理包含XML实体的XML文档,这些实体的URI可解析到预期控制范围之外的文档,导致该产品将不正确的文档嵌入其输出中。
常见影响 (3)
Confidentiality Read Application Data, Read Files or Directories
If the attacker is able to include a crafted DTD and a default entity resolver is enabled, the attacker may be able to access arbitrary files on the system. By submitting an XML file that defines an external entity with a file:// URI, an attacker can cause the processing application to read the co…
Integrity Bypass Protection Mechanism
An attacker may supply a crafted DTD using URIs with schemes such as http://, forcing the application to make outgoing HTTP requests to servers that the attacker cannot reach directly, which can be used to bypass firewall restrictions; hide the source of attacks such as port scanning; or otherwise l…
Availability DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory)
The product could consume excessive CPU cycles or memory using a URI that points to a large file, or a device that always returns data such as /dev/random. Alternately, the URI could reference a file that contains many nested or recursive entity references to further slow down parsing.
缓解措施 (1)
Implementation, System Configuration Many XML parsers and validators can be configured to disable external entity expansion.
CVE ID 标题 CVSS 风险等级 Published
CVE-2019-15983 Cisco Data Center Network Manager 代码问题漏洞 — Cisco Data Center Network Manager 4.9 - 2020-01-06
CVE-2019-3768 Dell RSA Authentication Manager 代码问题漏洞 — RSA Authentication Manager 6.5 - 2020-01-03
CVE-2019-10172 jackson-mapper-asl 代码问题漏洞 — jackson-mapper-asl 7.5 - 2019-11-18
CVE-2019-18227 Advantech WISE-PaaS/RMM 代码问题漏洞 — Advantech WISE-PaaS/RMM 7.5 - 2019-10-31
CVE-2019-12711 Cisco Unified Communications Manager和Cisco Unified Communications Manager Session Management Edition 代码问题漏洞 — Cisco Unified Communications Manager 9.1 - 2019-10-02
CVE-2019-10976 Mitsubishi Electric FR Configurator2 代码问题漏洞 — Mitsubishi Electric FR Configurator2 5.5 - 2019-07-25
CVE-2019-1903 Cisco Security Manager 代码问题漏洞 — Cisco Security Manager 9.1 - 2019-06-20
CVE-2019-10244 Eclipse Kura 代码问题漏洞 — Eclipse Kura 7.5 - 2019-04-09
CVE-2019-1698 Cisco IoT Field Network Director 代码问题漏洞 — Cisco IoT Field Network Director (IoT-FND) 4.9 - 2019-02-21
CVE-2019-3772 Pivotal Software Spring Integration 代码问题漏洞 — Spring Integration 9.8 - 2019-01-18
CVE-2019-3773 Pivotal Software Spring Web Services 代码问题漏洞 — Spring Web Services 9.8 - 2019-01-18
CVE-2019-3774 Pivotal Spring Batch 代码问题漏洞 — Spring Batch 9.8 - 2019-01-18
CVE-2018-17247 Elasticsearch Security 跨站脚本漏洞 — Elasticsearch 5.9 - 2018-12-20
CVE-2018-15444 Cisco Energy Management Suite 安全漏洞 — Cisco Energy Management Suite 6.3 - 2018-11-08
CVE-2018-17912 Fr. Sauter AG CASE Suite 安全漏洞 — CASE Suite 7.5 - 2018-11-02
CVE-2018-12544 Eclipse Vert.x 安全漏洞 — Eclipse Vert.x 9.8 - 2018-10-10
CVE-2018-10614 Wecon LeviStudioU 安全漏洞 — LeviStudioU 7.8 - 2018-10-09
CVE-2018-17889 Wecon PI Studio HMI和PI Studio 安全漏洞 — PI Studio HMI 6.5 - 2018-10-08
CVE-2018-0414 Cisco Secure Access Control Server 安全漏洞 — Cisco Secure Access Control Server Solution Engine (ACSE) 5.7 - 2018-10-05
CVE-2018-12471 Micro Focus SUSE Linux SMT 安全漏洞 — SMT 8.1 - 2018-10-04
CVE-2017-7464 Red Hat JBoss Enterprise Application Platform 安全漏洞 — JBoss 9.8 - 2018-07-27
CVE-2017-7545 jbpmmigration 安全漏洞 — jbpm-designer 6.5 - 2018-07-26
CVE-2018-10600 SEL AcSELerator Architect 安全漏洞 — AcSELerator Architect 9.8 - 2018-07-24
CVE-2016-9487 EpubCheck 安全漏洞 — EpubCheck 7.8 - 2018-07-13
CVE-2016-9491 ZOHO ManageEngine Applications Manager 信息泄露漏洞 — Applications Manager 4.9 - 2018-07-13
CVE-2017-7465 Red Hat JBoss Enterprise Application Platform 代码注入漏洞 — jboss 9.8 - 2018-06-27
CVE-2017-3206 Exadel Flamingo 安全漏洞 — Flamingo amf-serializer 9.8 - 2018-06-11
CVE-2018-10613 GE MDS PulseNET和MDS PulseNET Enterprise 安全漏洞 — MDS PulseNET and MDS PulseNET Enterprise 7.5 - 2018-06-04
CVE-2018-1077 Red Hat Spacewalk 安全漏洞 — spacewalk 7.5 - 2018-03-14
CVE-2018-0100 Cisco AnyConnect Secure Mobility Client Profile Editor 安全漏洞 — Cisco AnyConnect 6.1 - 2018-01-18

CWE-611(XML外部实体引用的不恰当限制(XXE)) 是常见的弱点类别,本平台收录该类弱点关联的 482 条 CVE 漏洞。