Description
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.
Remediation
References
http://packetstormsecurity.com/files/146339/SoapUI-5.3.0-Code-Execution.html
Related Vulnerabilities
CVE-2022-2900 Vulnerability in maven package org.webjars.npm:parse-url
CVE-2016-10539 Vulnerability in npm package negotiator
CVE-2018-12023 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-36599 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2022-24709 Vulnerability in npm package @awsui/components-react