On this page
Atomicorp WAF Rule 344372
Rule Summary
- Rule ID: 344372
- Status: Active
- Alert message: XML eXternal Entity: Local / Remote File Inclusion attempt
- Observed CWEs: CWE-79 (1), CWE-112 (1), CWE-200 (2), CWE-611 (23), CWE-918 (1)
- Revision: 2
- Rule severity: Critical
- Phase: 2 (request body)
- Request surfaces: Request body, JSON request data, SOAP request data
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “XML eXternal Entity: Local / Remote File Inclusion attempt” in the request body, JSON request data, SOAP request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2019-9670 | Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity Injection | zimbra collaboration suite | 9.8 (v3.1) | Critical |
| CVE-2022-3980 | Sophos Mobile managed on-premises - XML External Entity Injection | mobile | 9.8 (v3.1) | Critical |
| CVE-2025-2776 | SysAid On-Prem <= 23.3.40 - XML External Entity | sysaid | 9.8 (v3.1) | Critical |
| CVE-2025-2777 | SysAid On-Prem <= 23.3.40 - XML External Entity | sysaid | 9.8 (v3.1) | Critical |
| CVE-2016-6256 | SAP Business One for Android 1.2.3 - XML External Entity Injection | business one | 9.6 (v3.0) | Critical |
| CVE-2020-24589 | WSO2 API Manager <=3.1.0 - Blind XML External Entity Injection | api manager | 9.1 (v3.1) | Critical |
| CVE-2021-27931 | LumisXP <10.0.0 - Blind XML External Entity Attack | lumis experience platform | 9.1 (v3.1) | Critical |
| CVE-2022-31678 | VMWare Cloud Foundation NSX-V - XML External Entity (XXE) | cloud foundation | 9.1 (v3.1) | Critical |
| CVE-2026-69101 | Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint | tis | 8.3 (v4.0) | High |
| CVE-2025-68493 | Apache Struts XWork - XML External Entity Injection | struts | 8.1 (v3.1) | High |
| CVE-2016-3473 | Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injection | business intelligence publisher | 7.7 (v3.0) | High |
| CVE-2011-3600 | Apache OFBiz - XML External Entity Injection | ofbiz | 7.5 (v3.1) | High |
| CVE-2017-17762 | Episerver 7 - Blind XML External Entity Injection | episerver | 7.5 (v3.0) | High |
| CVE-2018-8033 | Apache OFBiz - XML External Entity Injection | ofbiz | 7.5 (v3.0) | High |
| CVE-2019-10266 | Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injection | cloud backup suite | 7.5 (v3.0) | High |
| CVE-2019-13608 | Citrix StoreFront Server - XML External Entity | storefront server | 7.5 (v3.1) | High |
| CVE-2019-9621 | Zimbra Collaboration Suite - SSRF | collaboration server | 7.5 (v3.1) | High |
| CVE-2019-9757 | LabKey Server 19.1.0 - XML External Entity (XXE) | labkey server | 7.5 (v3.1) | High |
| CVE-2020-11991 | Apache Cocoon 2.1.12 - XML Injection | cocoon | 7.5 (v3.1) | High |
| CVE-2022-2414 | FreeIPA - XML Entity Injection | dogtagpki | 7.5 (v3.1) | High |
| CVE-2022-38840 | Güralp MAN-EAM-0003 3.2.4 - XML External Entity (XXE) | man-eam-0003 | 7.5 (v3.1) | High |
| CVE-2024-6893 | Journyx - XML External Entities Injection (XXE) | journyx-jtime | 7.5 (v3.1) | High |
| CVE-2025-2775 | SysAid On-Prem <= 23.3.40 - XML External Entity | sysaid | 7.5 (v3.1) | High |
| CVE-2023-42344 | OpenCMS - XML external entity (XXE) | opencms | 7.3 (v3.1) | High |
| CVE-2015-5161 | Zend Framework 2.4.2 - PHP FPM XML eXternal Entity Injection | zend framework | 6.8 (v2.0) | Medium |
| CVE-2019-10263 | Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injection | cloud backup suite | 6.1 (v3.0) | Medium |
| CVE-2025-49493 | Akamai CloudTest < 60 2025.06.02 - XML External Entity (XXE) | CloudTest | 5.8 (v3.1) | Medium |
| CVE-2019-17554 | Apache Olingo OData 4.0 - XML External Entity Injection | olingo | 5.5 (v3.1) | Medium |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.