On this page
CWE-611: Improper Restriction of XML External Entity Reference
Weakness Summary
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
- Canonical source: MITRE CWE-611 (opens in a new tab)
- Published Atomicorp CVE observations: 38
- Distinct affected products in those observations: 35
- Active Atomicorp rules associated with this weakness: 34
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2018-12463 | Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection | fortify software security center | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2019-9670 | Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity Injection | zimbra collaboration suite | Attack Blocked by Atomicorp | 344372 |
| CVE-2022-28219 | Zoho ManageEngine ADAudit Plus <7600 - XML Entity Injection/Remote Code Execution | manageengine adaudit plus | Attack Blocked by Atomicorp | 344370 |
| CVE-2022-3980 | Sophos Mobile managed on-premises - XML External Entity Injection | mobile | Attack Blocked by Atomicorp | 344372 |
| CVE-2025-2776 | SysAid On-Prem <= 23.3.40 - XML External Entity | sysaid | Attack Blocked by Atomicorp | 330791 , 340152 , 344372 |
| CVE-2025-2777 | SysAid On-Prem <= 23.3.40 - XML External Entity | sysaid | Attack Blocked by Atomicorp | 330791 , 340152 , 344372 |
| CVE-2025-58360 | GeoServer - XML External Entity Injection | geoserver | Attack Blocked by Atomicorp | 391213 |
| CVE-2025-66516 | Apache Tika - XML External Entity Injection | tika | Attack Blocked by Atomicorp | 391213 |
| CVE-2016-6256 | SAP Business One for Android 1.2.3 - XML External Entity Injection | business one | Attack Blocked by Atomicorp | 344372 |
| CVE-2018-1821 | IBM Operational Decision Manager 8.x - XML External Entity Injection | operational decision manager | Attack Blocked by Atomicorp | 330791 , 340152 , 345493 |
| CVE-2020-24589 | WSO2 API Manager <=3.1.0 - Blind XML External Entity Injection | api manager | Attack Blocked by Atomicorp | 341256 , 344370 , 344372 , 380018 |
| CVE-2021-27931 | LumisXP <10.0.0 - Blind XML External Entity Attack | lumis experience platform | Attack Blocked by Atomicorp | 344372 , 392301 |
| CVE-2021-37425 | Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE) | mobiletogether server | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2022-31678 | VMWare Cloud Foundation NSX-V - XML External Entity (XXE) | cloud foundation | Attack Blocked by Atomicorp | 344372 |
| CVE-2016-8526 | Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scripting | airwave | Attack Blocked by Atomicorp | 333141 , 341256 , 342259 , 344370 , 346755 , 350147 , 350148 |
| CVE-2025-54988 | Apache Tika - XXE Injection | tika | Attack Blocked by Atomicorp | 391213 |
| CVE-2024-22024 | Ivanti Connect Secure - XXE | connect secure | Attack Blocked by Atomicorp | 380019 |
| CVE-2026-69101 | Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint | tis | Attack Blocked by Atomicorp | 330791 , 340152 , 344360 , 344370 , 344372 , 344373 , 398008 |
| CVE-2025-68493 | Apache Struts XWork - XML External Entity Injection | struts | Attack Blocked by Atomicorp | 344370 , 344372 |
| CVE-2011-3600 | Apache OFBiz - XML External Entity Injection | ofbiz | Attack Blocked by Atomicorp | 344372 |
| CVE-2017-17762 | Episerver 7 - Blind XML External Entity Injection | episerver | Attack Blocked by Atomicorp | 344372 |
| CVE-2019-10266 | Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injection | cloud backup suite | Attack Blocked by Atomicorp | 344372 |
| CVE-2019-13608 | Citrix StoreFront Server - XML External Entity | storefront server | Attack Blocked by Atomicorp | 344372 , 391213 |
| CVE-2019-8086 | Adobe Experience Manager - XML External Entity Injection | experience manager | Attack Blocked by Atomicorp | 330925 |
| CVE-2019-9757 | LabKey Server 19.1.0 - XML External Entity (XXE) | labkey server | Attack Blocked by Atomicorp | 340029 , 341256 , 342259 , 344360 , 344372 , 380018 |
| CVE-2020-11991 | Apache Cocoon 2.1.12 - XML Injection | cocoon | Attack Blocked by Atomicorp | 344372 |
| CVE-2022-2414 | FreeIPA - XML Entity Injection | dogtagpki | Attack Blocked by Atomicorp | 344372 |
| CVE-2022-38840 | Güralp MAN-EAM-0003 3.2.4 - XML External Entity (XXE) | man-eam-0003 | Attack Blocked by Atomicorp | 344360 , 344370 , 344372 , 380018 |
| CVE-2024-38653 | Ivanti Avalanche SmartDeviceServer - XML External Entity | avalanche | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2024-45293 | TablePress < 2.4.3 - XXE Injection | tablepress | Detected by Atomicorp | 377360 |
| CVE-2024-6893 | Journyx - XML External Entities Injection (XXE) | journyx-jtime | Attack Blocked by Atomicorp | 344360 , 344370 , 344372 |
| CVE-2025-2775 | SysAid On-Prem <= 23.3.40 - XML External Entity | sysaid | Attack Blocked by Atomicorp | 330791 , 340152 , 344372 |
| CVE-2023-42344 | OpenCMS - XML external entity (XXE) | opencms | Attack Blocked by Atomicorp | 330791 , 340152 , 344372 |
| CVE-2018-1247 | RSA Authentication Manager 8.2.1.4.0-build1394922 / < 8.3 P1 - XML External Entity Injection / Cross-Site Flashing / DOM Cross-Site Scripting | authentication manager | Attack Blocked by Atomicorp | 392301 |
| CVE-2017-3548 | Oracle PeopleSoft - 'PeopleSoftServiceListeningConnector' XML External Entity via DOCTYPE | peoplesoft enterprise peopletools | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2025-49493 | Akamai CloudTest < 60 2025.06.02 - XML External Entity (XXE) | CloudTest | Attack Blocked by Atomicorp | 344372 |
| CVE-2019-17554 | Apache Olingo OData 4.0 - XML External Entity Injection | olingo | Attack Blocked by Atomicorp | 344372 , 345493 |
| CVE-2018-6225 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | Attack Blocked by Atomicorp | 333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 330791 | Active | disruptive (deny) |
| 330925 | Active | disruptive (deny) |
| 333141 | Active | disruptive (deny) |
| 337209 | Active | disruptive (deny) |
| 337210 | Active | disruptive (deny) |
| 337211 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340145 | Active | disruptive (deny) |
| 340147 | Active | disruptive (deny) |
| 340148 | Active | disruptive (deny) |
| 340149 | Active | disruptive (deny) |
| 340152 | Active | disruptive (deny) |
| 340156 | Active | disruptive (deny) |
| 341145 | Active | disruptive (deny) |
| 341245 | Active | disruptive (deny) |
| 341256 | Active | disruptive (deny) |
| 342259 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 344372 | Active | disruptive (deny) |
| 344373 | Active | disruptive (deny) |
| 345493 | Active | non-disruptive (pass) |
| 346755 | Active | disruptive (deny) |
| 350147 | Active | disruptive (deny) |
| 350148 | Active | disruptive (deny) |
| 377360 | Active | non-disruptive (pass) |
| 380018 | Active | disruptive (deny) |
| 380019 | Active | disruptive (deny) |
| 390572 | Active | disruptive (deny) |
| 390585 | Active | disruptive (deny) |
| 390704 | Active | disruptive (deny) |
| 391213 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 398008 | Active | non-disruptive (pass) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims: