KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (.knwf), aka AP-17730.
https://zigrin.com/advisories/knime-analytics-platform-external-xml-entity-injection/
https://www.knime.com/whats-new-in-knime-45