
MAL-006: XML External Entity in "Try It" in WSO2 ESB
An error-based XML External Entity (XXE) attack was identified in the WSO2 ESB "Try It" tool.
The vendor replied that "Try it is recommended to be disabled in production" and no public disclosure was made.
This vulnerability requires:
More details and the exploitation process can be found in this PDF.