
MAL-007: XML External Entity via Local Registry Entries in WSO2 ESB
An inline XML External Entity (XXE) attack was identified in the WSO2 ESB “Local Entities” tool.
The vendor replied that this vulnerability was "Fixed in WUM" and no public disclosure was made.
This vulnerability requires:
More details and the exploitation process can be found in this PDF.