9.3
CVSSv2

CVE-2014-1202

Published: 25/01/2014 Updated: 28/01/2014
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The WSDL/WADL import functionality in SoapUI prior to 4.6.4 allows remote malicious users to execute arbitrary Java code via a crafted request parameter in a WSDL file.

Vulnerable Product Search on Vulmon Subscribe to Product

smartbear soapui

smartbear soapui 4.6.2

smartbear soapui 4.0

eviware soapui 3.5.1

eviware soapui 3.5

smartbear soapui 4.5.1

smartbear soapui 4.5

eviware soapui 3.0.1

eviware soapui 2.5.1

smartbear soapui 4.0.1

eviware soapui 3.6.1

eviware soapui 3.6

smartbear soapui 4.6.1

smartbear soapui 4.6.0

smartbear soapui 4.5.2

Vendor Advisories

The WSDL/WADL import functionality in SoapUI before 464 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file ...

Exploits

# Exploit Title: SoapUI Remote Code Execution # Date: 251213 # Exploit Author: Barak Tawily # Vendor Homepage: <wwwsoapuiorg/> wwwsoapuiorg/ # Software Link: <wwwsoapuiorg/Downloads/download-soapui-pro-trialhtml> wwwsoapuiorg/Downloads/download-soapui-pro-trialhtml # Version: vulnerable before 4 ...
SoapUI versions prior to 464 suffer from a remote code execution vulnerability ...