9.3

CVE-2014-1202

Exploit
The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eviware ≫ Soapui Version 2.5.1
Eviware ≫ Soapui Version 3.0.1
Eviware ≫ Soapui Version 3.5
Eviware ≫ Soapui Version 3.5.1
Eviware ≫ Soapui Version 3.6
Eviware ≫ Soapui Version 3.6.1
Smartbear ≫ Soapui Version <= 4.6.3
Smartbear ≫ Soapui Version 4.0
Smartbear ≫ Soapui Version 4.0 Update beta1
Smartbear ≫ Soapui Version 4.0 Update beta2
Smartbear ≫ Soapui Version 4.0.1
Smartbear ≫ Soapui Version 4.5
Smartbear ≫ Soapui Version 4.5.1
Smartbear ≫ Soapui Version 4.5.2
Smartbear ≫ Soapui Version 4.6.0
Smartbear ≫ Soapui Version 4.6.1
Smartbear ≫ Soapui Version 4.6.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.67% 0.938
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://baraktawily.blogspot.com/2014/01/soapui-code-execution-vulnerability-cve.html
http://packetstormsecurity.com/files/124773/SoapUI-Remote-Code-Execution.html
Exploit
http://www.exploit-db.com/exploits/30908
Exploit
http://www.youtube.com/watch?v=3lCLE64rsc0
https://github.com/SmartBear/soapui/blob/master/RELEASENOTES.txt