CWE-611Base4 in KEV

Improper Restriction of XML External Entity Reference

Draft in the CWE catalog · 491 CVEs mapped

491
CVEs mapped
4
In KEV
6.9
Median CVSS
What it is

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Recent examples
5.3cvss
CVE-2026-17444

CVE-2026-17444 - MEDIUM Severity Vulnerability

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

MEDIUMno explanation yet
0%
epss
5.3cvss
CVE-2026-17443

CVE-2026-17443 - MEDIUM Severity Vulnerability

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.

MEDIUMno explanation yet
0%
epss
7.7cvss
CVE-2026-81832

CVE-2026-81832 - HIGH Severity Vulnerability

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-611
Abstraction
Base
Structure
Simple
Status
Draft
References (6)