Back

HIGH

SoapUI: remote code execution when processing WSDL

Published Jan 25, 2014

Description

The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.

Affected products

Remediation

Red Hat statement

Not affected. Red Hat JBoss SOA Platform 4.3 and 5.3 support the SOAPClient action, which will use the SoapUI library to make calls to external web services. However, these products use SoapUI 1.7.1, while the vulnerable property expansion feature was not introduced until SoapUI 2.5. Therefore no Red Hat products are affected by this flaw.

Metrics

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 25, 2014
Updated Aug 6, 2024
Reserved Jan 7, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 15, 2014
GHSA-C2FP-MPMM-CQXV