HTTP: Multiple Product XML External Entity Injection Information Disclosure

This signature detects attempts to exploit a known vulnerability through External Entity Injection in various products. A successful attack can lead to unauthorized information disclosure, denial of service, request forgery and security policies bypass.

Extended Description

XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue.

Affected Products

Apache drill

References

BugTraq: 103230 99387 99398 106390

CVE: CVE-2025-49544

URL: http://www.zerodayinitiative.com/advisories/ZDI-22-585/ https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1134596 http://www.zerodayinitiative.com/advisories/ZDI-22-1128/ https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2022-005.pdf http://www.zerodayinitiative.com/advisories/ZDI-23-1043/ http://www.zerodayinitiative.com/advisories/ZDI-23-1037/ http://www.zerodayinitiative.com/advisories/ZDI-23-1039/ https://www.cisa.gov/news-events/ics-advisories/icsa-23-080-05 http://www.zerodayinitiative.com/advisories/ZDI-23-1038/ https://download.sew-eurodrive.com/download/pdf/31965520.pdf http://www.zerodayinitiative.com/advisories/ZDI-24-582/ https://lists.apache.org/thread/9tt0q4bdjwgw0dz0l9knqxjnpb5y6zsl

Short Name
HTTP:STC:XXE-INJ
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2017-0045 CVE-2017-0170 CVE-2017-8557 CVE-2017-8710 CVE-2018-0878 CVE-2018-8533 CVE-2019-0537 CVE-2019-0948 CVE-2020-26981 CVE-2022-1018 CVE-2022-36969 CVE-2022-45468 CVE-2022-45876 CVE-2022-46286 CVE-2022-46300 CVE-2023-48362 CVE-2024-1167 CVE-2025-49544 Disclosure Entity External Information Injection Multiple Product XML bid:103230 bid:106390 bid:99387 bid:99398
Release Date
03/21/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3833
False Positive
Unknown
Vendors

Apache

CVSS Score

4.3

2.1

2.6

Found a potential security threat?