CVE-2016-4312 | WSO2 Identity Server up to 5.1.0 eval-policy-submit.jsp xml external entity reference (EDB-40239 / BID-92485)
A vulnerability was found in WSO2 Identity Server up to 5.1.0 and classified as critical. This issue affects some unknown processing of the file entitlement/eval-policy-submit.jsp. The manipulation leads to xml external entity reference.
The identification of this vulnerability is CVE-2016-4312. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.