// For flags

CVE-2014-1202

SoapUI 4.6.3 - Remote Code Execution

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.

La funcionalidad de importación WSDL/WADL en SoapUI anteriores a 4.6.4 permite a atacantes remotos ejecutar código Java arbitrario a través de parámetros de petición manipulados en un fichero WSDL.

SoapUI versions prior to 4.6.4 suffer from a remote code execution vulnerability.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-01-07 CVE Reserved
  • 2014-01-14 CVE Published
  • 2014-01-14 First Exploit
  • 2024-08-06 CVE Updated
  • 2024-08-12 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Eviware
Search vendor "Eviware"
Soapui
Search vendor "Eviware" for product "Soapui"
2.5.1
Search vendor "Eviware" for product "Soapui" and version "2.5.1"
-
Affected
Eviware
Search vendor "Eviware"
Soapui
Search vendor "Eviware" for product "Soapui"
3.0.1
Search vendor "Eviware" for product "Soapui" and version "3.0.1"
-
Affected
Eviware
Search vendor "Eviware"
Soapui
Search vendor "Eviware" for product "Soapui"
3.5
Search vendor "Eviware" for product "Soapui" and version "3.5"
-
Affected
Eviware
Search vendor "Eviware"
Soapui
Search vendor "Eviware" for product "Soapui"
3.5.1
Search vendor "Eviware" for product "Soapui" and version "3.5.1"
-
Affected
Eviware
Search vendor "Eviware"
Soapui
Search vendor "Eviware" for product "Soapui"
3.6
Search vendor "Eviware" for product "Soapui" and version "3.6"
-
Affected
Eviware
Search vendor "Eviware"
Soapui
Search vendor "Eviware" for product "Soapui"
3.6.1
Search vendor "Eviware" for product "Soapui" and version "3.6.1"
-
Affected
Smartbear
Search vendor "Smartbear"
Soapui
Search vendor "Smartbear" for product "Soapui"
<= 4.6.3
Search vendor "Smartbear" for product "Soapui" and version " <= 4.6.3"
-
Affected
Smartbear
Search vendor "Smartbear"
Soapui
Search vendor "Smartbear" for product "Soapui"
4.0
Search vendor "Smartbear" for product "Soapui" and version "4.0"
-
Affected
Smartbear
Search vendor "Smartbear"
Soapui
Search vendor "Smartbear" for product "Soapui"
4.0
Search vendor "Smartbear" for product "Soapui" and version "4.0"
beta1
Affected
Smartbear
Search vendor "Smartbear"
Soapui
Search vendor "Smartbear" for product "Soapui"
4.0
Search vendor "Smartbear" for product "Soapui" and version "4.0"
beta2
Affected
Smartbear
Search vendor "Smartbear"
Soapui
Search vendor "Smartbear" for product "Soapui"
4.0.1
Search vendor "Smartbear" for product "Soapui" and version "4.0.1"
-
Affected
Smartbear
Search vendor "Smartbear"
Soapui
Search vendor "Smartbear" for product "Soapui"
4.5
Search vendor "Smartbear" for product "Soapui" and version "4.5"
-
Affected
Smartbear
Search vendor "Smartbear"
Soapui
Search vendor "Smartbear" for product "Soapui"
4.5.1
Search vendor "Smartbear" for product "Soapui" and version "4.5.1"
-
Affected
Smartbear
Search vendor "Smartbear"
Soapui
Search vendor "Smartbear" for product "Soapui"
4.5.2
Search vendor "Smartbear" for product "Soapui" and version "4.5.2"
-
Affected
Smartbear
Search vendor "Smartbear"
Soapui
Search vendor "Smartbear" for product "Soapui"
4.6.0
Search vendor "Smartbear" for product "Soapui" and version "4.6.0"
-
Affected
Smartbear
Search vendor "Smartbear"
Soapui
Search vendor "Smartbear" for product "Soapui"
4.6.1
Search vendor "Smartbear" for product "Soapui" and version "4.6.1"
-
Affected
Smartbear
Search vendor "Smartbear"
Soapui
Search vendor "Smartbear" for product "Soapui"
4.6.2
Search vendor "Smartbear" for product "Soapui" and version "4.6.2"
-
Affected