CVE-2014-1202
25.01.2014, 01:55
The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.
Code Injection
Vendor | Product | Version |
---|---|---|
eviware | soapui | 2.5.1 |
eviware | soapui | 3.0.1 |
eviware | soapui | 3.5 |
eviware | soapui | 3.5.1 |
eviware | soapui | 3.6 |
eviware | soapui | 3.6.1 |
smartbear | soapui | 𝑥 ≤ 4.6.3 |
smartbear | soapui | 4.0 |
smartbear | soapui | 4.0 |
smartbear | soapui | 4.0 |
smartbear | soapui | 4.0.1 |
smartbear | soapui | 4.5 |
smartbear | soapui | 4.5.1 |
smartbear | soapui | 4.5.2 |
smartbear | soapui | 4.6.0 |
smartbear | soapui | 4.6.1 |
smartbear | soapui | 4.6.2 |
𝑥
= Vulnerable software versions
References