Description
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.
Remediation
References
http://packetstormsecurity.com/files/146339/SoapUI-5.3.0-Code-Execution.html
Related Vulnerabilities
CVE-2019-10797 Vulnerability in maven package org.wso2.transport.http:org.wso2.transport.http.netty
CVE-2020-14967 Vulnerability in maven package org.webjars.bowergithub.kjur:jsrsasign
CVE-2019-10440 Vulnerability in maven package org.jenkins-ci.plugins:neoload-jenkins-plugin
CVE-2023-5654 Vulnerability in npm package react-devtools-core
CVE-2015-6420 Vulnerability in maven package commons-collections:commons-collections