9.8
CVSSv3

CVE-2020-12835

Published: 20/05/2020 Updated: 21/07/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

smartbear readyapi 3.2.5

Exploits

Protection Licensing Toolkit ReadyAPI version 325 suffers from an unsafe deserialization vulnerability that allows for remote code execution ...

Mailing Lists

Advisory ID: SYSS-2019-039 Product: Protection Licensing Toolkit, SoapUI/LoadUI/ServiceV Pro Manufacturer: jProductivity LLC, SmartBear Software Affected Version(s): - ReadyAPI 325 Tested Version(s): ReadyAPI 325 Vulnerability Type: Unsafe deserialization/remote code execution (CWE-502) Risk Level: High Solution Status: Open Manufacturer Notifi ...