CVE-2014-1202
Code injection via property expansion in SoapUI
EPSS 7.7%
Description
The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.
How to fix CVE-2014-1202
To remediate CVE-2014-1202, upgrade the affected package to a fixed version below.
- Maven/com.smartbear.soapui:soapui—upgrade to 4.6.4 or later
Is CVE-2014-1202 being exploited?
Moderate — EPSS is 7.7%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 4.6.4