Threats Tagged 'cwe-611'
View all threats tagged with 'cwe-611'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-611'
Click on any threat for detailed analysis and mitigation recommendations
FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw. Join the discussion | CVE Database V5 | 09/25/2026, 14:32:52 UTC Added: 09/25/2026, 14:48:38 UTC |
0 http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any security configuration. With the JDK's default settings, the parser resolves DOCTYPE declarations, external general and parameter entities, and external DTDs.An application that uses these decoders to parse untrusted XML is vulnerable to XML External Entity (XXE) attacks. An attacker can craft a request that discloses local files readable by the service process, performs server-side request forgery (SSRF) against internal network resources, and/or causes denial of service through entity expansion. Versions 0.24.1 and 1.0.0-M39 fix the issue. Join the discussion | CVE Database V5 | 09/24/2026, 17:48:09 UTC Added: 09/24/2026, 18:04:14 UTC |
0 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. Join the discussion | CVE Database V5 | 09/23/2026, 21:38:08 UTC Added: 09/23/2026, 21:48:15 UTC |
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw. Join the discussion | CVE Database V5 | 09/23/2026, 15:43:57 UTC Added: 09/23/2026, 19:03:14 UTC |
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references. Join the discussion | CVE Database V5 | 09/22/2026, 22:16:27 UTC Added: 09/22/2026, 22:33:33 UTC |
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references. Join the discussion | CVE Database V5 | 09/22/2026, 21:42:56 UTC Added: 09/22/2026, 21:48:27 UTC |
0 MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5 until 16.4.1, MerlinReader creates a DocumentBuilder with default settings while parsing XML from the ZTIMEINTERVALS column of a Merlin project SQLite database, leaving doctype declarations and external entities enabled. A crafted database can cause the parser to read an arbitrary local file, although MPXJ's subsequent handling of the parsed XML makes disclosure of the file contents unlikely. This issue is fixed in version 16.4.1. Join the discussion | CVE Database V5 | 09/22/2026, 19:56:08 UTC Added: 09/22/2026, 20:04:01 UTC |
0 IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Classes for Java could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to XML external entity injection in MQRFH2 header processing. Join the discussion | CVE Database V5 | 09/15/2026, 17:08:05 UTC Added: 09/15/2026, 17:32:29 UTC |
0 IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to read files from a vulnerable .NET client or cause limited denial of service due to improper handling of XML external entities in RFH2 folder parsing. Join the discussion | CVE Database V5 | 09/15/2026, 17:07:31 UTC Added: 09/15/2026, 17:32:29 UTC |
IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resource. Join the discussion | CVE Database V5 | 09/15/2026, 17:02:39 UTC Added: 09/15/2026, 17:32:31 UTC |
Showing 1 to 10 of 154 results