On this page

CWE-611: Improper Restriction of XML External Entity Reference

Weakness Summary

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

  • Canonical source: MITRE CWE-611 (opens in a new tab)
  • Published Atomicorp CVE observations: 38
  • Distinct affected products in those observations: 35
  • Active Atomicorp rules associated with this weakness: 34

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2018-12463Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injectionfortify software security centerAttack Blocked by Atomicorp330791 , 340152
CVE-2019-9670Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity Injectionzimbra collaboration suiteAttack Blocked by Atomicorp344372
CVE-2022-28219Zoho ManageEngine ADAudit Plus <7600 - XML Entity Injection/Remote Code Executionmanageengine adaudit plusAttack Blocked by Atomicorp344370
CVE-2022-3980Sophos Mobile managed on-premises - XML External Entity InjectionmobileAttack Blocked by Atomicorp344372
CVE-2025-2776SysAid On-Prem <= 23.3.40 - XML External EntitysysaidAttack Blocked by Atomicorp330791 , 340152 , 344372
CVE-2025-2777SysAid On-Prem <= 23.3.40 - XML External EntitysysaidAttack Blocked by Atomicorp330791 , 340152 , 344372
CVE-2025-58360GeoServer - XML External Entity InjectiongeoserverAttack Blocked by Atomicorp391213
CVE-2025-66516Apache Tika - XML External Entity InjectiontikaAttack Blocked by Atomicorp391213
CVE-2016-6256SAP Business One for Android 1.2.3 - XML External Entity Injectionbusiness oneAttack Blocked by Atomicorp344372
CVE-2018-1821IBM Operational Decision Manager 8.x - XML External Entity Injectionoperational decision managerAttack Blocked by Atomicorp330791 , 340152 , 345493
CVE-2020-24589WSO2 API Manager <=3.1.0 - Blind XML External Entity Injectionapi managerAttack Blocked by Atomicorp341256 , 344370 , 344372 , 380018
CVE-2021-27931LumisXP <10.0.0 - Blind XML External Entity Attacklumis experience platformAttack Blocked by Atomicorp344372 , 392301
CVE-2021-37425Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE)mobiletogether serverAttack Blocked by Atomicorp330791 , 340152
CVE-2022-31678VMWare Cloud Foundation NSX-V - XML External Entity (XXE)cloud foundationAttack Blocked by Atomicorp344372
CVE-2016-8526Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site ScriptingairwaveAttack Blocked by Atomicorp333141 , 341256 , 342259 , 344370 , 346755 , 350147 , 350148
CVE-2025-54988Apache Tika - XXE InjectiontikaAttack Blocked by Atomicorp391213
CVE-2024-22024Ivanti Connect Secure - XXEconnect secureAttack Blocked by Atomicorp380019
CVE-2026-69101Datavane TIS v5.0.0 XXE Injection via doEditWorkflow EndpointtisAttack Blocked by Atomicorp330791 , 340152 , 344360 , 344370 , 344372 , 344373 , 398008
CVE-2025-68493Apache Struts XWork - XML External Entity InjectionstrutsAttack Blocked by Atomicorp344370 , 344372
CVE-2011-3600Apache OFBiz - XML External Entity InjectionofbizAttack Blocked by Atomicorp344372
CVE-2017-17762Episerver 7 - Blind XML External Entity InjectionepiserverAttack Blocked by Atomicorp344372
CVE-2019-10266Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injectioncloud backup suiteAttack Blocked by Atomicorp344372
CVE-2019-13608Citrix StoreFront Server - XML External Entitystorefront serverAttack Blocked by Atomicorp344372 , 391213
CVE-2019-8086Adobe Experience Manager - XML External Entity Injectionexperience managerAttack Blocked by Atomicorp330925
CVE-2019-9757LabKey Server 19.1.0 - XML External Entity (XXE)labkey serverAttack Blocked by Atomicorp340029 , 341256 , 342259 , 344360 , 344372 , 380018
CVE-2020-11991Apache Cocoon 2.1.12 - XML InjectioncocoonAttack Blocked by Atomicorp344372
CVE-2022-2414FreeIPA - XML Entity InjectiondogtagpkiAttack Blocked by Atomicorp344372
CVE-2022-38840Güralp MAN-EAM-0003 3.2.4 - XML External Entity (XXE)man-eam-0003Attack Blocked by Atomicorp344360 , 344370 , 344372 , 380018
CVE-2024-38653Ivanti Avalanche SmartDeviceServer - XML External EntityavalancheAttack Blocked by Atomicorp330791 , 340152
CVE-2024-45293TablePress < 2.4.3 - XXE InjectiontablepressDetected by Atomicorp377360
CVE-2024-6893Journyx - XML External Entities Injection (XXE)journyx-jtimeAttack Blocked by Atomicorp344360 , 344370 , 344372
CVE-2025-2775SysAid On-Prem <= 23.3.40 - XML External EntitysysaidAttack Blocked by Atomicorp330791 , 340152 , 344372
CVE-2023-42344OpenCMS - XML external entity (XXE)opencmsAttack Blocked by Atomicorp330791 , 340152 , 344372
CVE-2018-1247RSA Authentication Manager 8.2.1.4.0-build1394922 / < 8.3 P1 - XML External Entity Injection / Cross-Site Flashing / DOM Cross-Site Scriptingauthentication managerAttack Blocked by Atomicorp392301
CVE-2017-3548Oracle PeopleSoft - 'PeopleSoftServiceListeningConnector' XML External Entity via DOCTYPEpeoplesoft enterprise peopletoolsAttack Blocked by Atomicorp330791 , 340152
CVE-2025-49493Akamai CloudTest < 60 2025.06.02 - XML External Entity (XXE)CloudTestAttack Blocked by Atomicorp344372
CVE-2019-17554Apache Olingo OData 4.0 - XML External Entity InjectionolingoAttack Blocked by Atomicorp344372 , 345493
CVE-2018-6225Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilitiesemail encryption gatewayAttack Blocked by Atomicorp333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704

Associated Atomicorp WAF Rules

RuleStatusBehavior
330791Activedisruptive (deny)
330925Activedisruptive (deny)
333141Activedisruptive (deny)
337209Activedisruptive (deny)
337210Activedisruptive (deny)
337211Activedisruptive (deny)
340029Activedisruptive (deny)
340145Activedisruptive (deny)
340147Activedisruptive (deny)
340148Activedisruptive (deny)
340149Activedisruptive (deny)
340152Activedisruptive (deny)
340156Activedisruptive (deny)
341145Activedisruptive (deny)
341245Activedisruptive (deny)
341256Activedisruptive (deny)
342259Activedisruptive (deny)
344360Activedisruptive (deny)
344370Activedisruptive (deny)
344372Activedisruptive (deny)
344373Activedisruptive (deny)
345493Activenon-disruptive (pass)
346755Activedisruptive (deny)
350147Activedisruptive (deny)
350148Activedisruptive (deny)
377360Activenon-disruptive (pass)
380018Activedisruptive (deny)
380019Activedisruptive (deny)
390572Activedisruptive (deny)
390585Activedisruptive (deny)
390704Activedisruptive (deny)
391213Activedisruptive (deny)
392301Activedisruptive (deny)
398008Activenon-disruptive (pass)

MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:

CAPEC-221 (opens in a new tab)