Description
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.
Remediation
References
http://packetstormsecurity.com/files/146339/SoapUI-5.3.0-Code-Execution.html
Related Vulnerabilities
CVE-2016-6794 Vulnerability in maven package org.apache.tomcat:tomcat-util
CVE-2017-17068 Vulnerability in npm package auth0-js
CVE-2020-8203 Vulnerability in maven package org.webjars.bower:lodash
CVE-2020-7752 Vulnerability in npm package systeminformation
CVE-2022-24785 Vulnerability in maven package org.webjars.bowergithub.moment:moment