Page History
...
As per the Security Advisory (WSO2-2017-0345), WSO2 EI 6.5.0 uses OAEP for data encryption in addition to the RSA algorithm (which is used in the ESB profile of WSO2 ESB 5.0.0). Therefore, the internally-encrypted data in your current databases (such as datasource configurations, syslog passwords, user store configurations, keystore registry entries, service security policies, event publisher configurations, event receiver configurations, and event sink configurations), as well as data encrypted using secure vault (such as plain text passwords in configuration files and synapse configurations) should be re-encrypted using OAEP.
...