CVE-2016-10097
XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM – Access Management 10.1.0 allows remote attackers to read arbitrary files via the SAMLRequest parameter.
Date published : 2017-01-02
http://www.securityfocus.com/bid/95174
http://www.cloudscan.me/2016/03/xxe-dork-open-am-1010-xml-injection.html