The document discusses security challenges with service-oriented architectures (SOA) and web services. It introduces SOA, web services, and web 2.0, and describes the growing adoption of these technologies. It then presents the XML/SOA threat model, which includes payload/content threats that target back-end systems or end users, XML misuse/abuse through injection and structure manipulation attacks, and infrastructure attacks. Examples of specific attacks are provided like SQL injection, XML entity expansion attacks, and denial of service attacks.