Description
The SOAP endpoint supports the WS-Addressing technology, enabling clients to specify the destination for SOAP responses. An unauthenticated attacker could use it to send requests to other servers (Blind SSRF).
Remediation
Disable WS-Addressing if it's not required
References
Related Vulnerabilities
Oracle Business Intelligence Convert XXE CVE-2019-2767
Xdebug remote code execution via xdebug.remote_connect_back
Deserialization of Untrusted Data (Java JSON Deserialization) Genson
WordPress 4.4.x Multiple Vulnerabilities (4.4 - 4.4.9)
Oracle Business Intelligence ReportTemplateService XXE CVE-2019-2616