Description
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.
Remediation
References
http://packetstormsecurity.com/files/146339/SoapUI-5.3.0-Code-Execution.html
Related Vulnerabilities
CVE-2022-45392 Vulnerability in maven package io.jenkins.plugins:cavisson-ns-nd-integration
CVE-2023-22477 Vulnerability in npm package mercurius
CVE-2023-40810 Vulnerability in maven package org.opencrx:opencrx-core-models
CVE-2022-31166 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore