On this page

Atomicorp WAF Rule 344372

Rule Summary

  • Rule ID: 344372
  • Status: Active
  • Alert message: XML eXternal Entity: Local / Remote File Inclusion attempt
  • Observed CWEs: CWE-79 (1), CWE-112 (1), CWE-200 (2), CWE-611 (23), CWE-918 (1)
  • Revision: 2
  • Rule severity: Critical
  • Phase: 2 (request body)
  • Request surfaces: Request body, JSON request data, SOAP request data
  • Rule action: deny
  • HTTP status: 403
  • Logging: log, auditlog

Description

This rule detects behavior identified by its current alert as “XML eXternal Entity: Local / Remote File Inclusion attempt” in the request body, JSON request data, SOAP request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2019-9670Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity Injectionzimbra collaboration suite9.8 (v3.1)Critical
CVE-2022-3980Sophos Mobile managed on-premises - XML External Entity Injectionmobile9.8 (v3.1)Critical
CVE-2025-2776SysAid On-Prem <= 23.3.40 - XML External Entitysysaid9.8 (v3.1)Critical
CVE-2025-2777SysAid On-Prem <= 23.3.40 - XML External Entitysysaid9.8 (v3.1)Critical
CVE-2016-6256SAP Business One for Android 1.2.3 - XML External Entity Injectionbusiness one9.6 (v3.0)Critical
CVE-2020-24589WSO2 API Manager <=3.1.0 - Blind XML External Entity Injectionapi manager9.1 (v3.1)Critical
CVE-2021-27931LumisXP <10.0.0 - Blind XML External Entity Attacklumis experience platform9.1 (v3.1)Critical
CVE-2022-31678VMWare Cloud Foundation NSX-V - XML External Entity (XXE)cloud foundation9.1 (v3.1)Critical
CVE-2026-69101Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpointtis8.3 (v4.0)High
CVE-2025-68493Apache Struts XWork - XML External Entity Injectionstruts8.1 (v3.1)High
CVE-2016-3473Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injectionbusiness intelligence publisher7.7 (v3.0)High
CVE-2011-3600Apache OFBiz - XML External Entity Injectionofbiz7.5 (v3.1)High
CVE-2017-17762Episerver 7 - Blind XML External Entity Injectionepiserver7.5 (v3.0)High
CVE-2018-8033Apache OFBiz - XML External Entity Injectionofbiz7.5 (v3.0)High
CVE-2019-10266Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injectioncloud backup suite7.5 (v3.0)High
CVE-2019-13608Citrix StoreFront Server - XML External Entitystorefront server7.5 (v3.1)High
CVE-2019-9621Zimbra Collaboration Suite - SSRFcollaboration server7.5 (v3.1)High
CVE-2019-9757LabKey Server 19.1.0 - XML External Entity (XXE)labkey server7.5 (v3.1)High
CVE-2020-11991Apache Cocoon 2.1.12 - XML Injectioncocoon7.5 (v3.1)High
CVE-2022-2414FreeIPA - XML Entity Injectiondogtagpki7.5 (v3.1)High
CVE-2022-38840Güralp MAN-EAM-0003 3.2.4 - XML External Entity (XXE)man-eam-00037.5 (v3.1)High
CVE-2024-6893Journyx - XML External Entities Injection (XXE)journyx-jtime7.5 (v3.1)High
CVE-2025-2775SysAid On-Prem <= 23.3.40 - XML External Entitysysaid7.5 (v3.1)High
CVE-2023-42344OpenCMS - XML external entity (XXE)opencms7.3 (v3.1)High
CVE-2015-5161Zend Framework 2.4.2 - PHP FPM XML eXternal Entity Injectionzend framework6.8 (v2.0)Medium
CVE-2019-10263Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injectioncloud backup suite6.1 (v3.0)Medium
CVE-2025-49493Akamai CloudTest < 60 2025.06.02 - XML External Entity (XXE)CloudTest5.8 (v3.1)Medium
CVE-2019-17554Apache Olingo OData 4.0 - XML External Entity Injectionolingo5.5 (v3.1)Medium

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-79CVE-2019-10263
CWE-112CVE-2025-68493
CWE-200CVE-2016-3473 , CVE-2018-8033
CWE-611CVE-2019-9670 , CVE-2022-3980 , CVE-2025-2776 , CVE-2025-2777 , CVE-2016-6256 , CVE-2020-24589 , CVE-2021-27931 , CVE-2022-31678 , CVE-2026-69101 , CVE-2025-68493 , CVE-2011-3600 , CVE-2017-17762 , CVE-2019-10266 , CVE-2019-13608 , CVE-2019-9757 , CVE-2020-11991 , CVE-2022-2414 , CVE-2022-38840 , CVE-2024-6893 , CVE-2025-2775 , CVE-2023-42344 , CVE-2025-49493 , CVE-2019-17554
CWE-918CVE-2019-9621