CVE-2014-1202: Code Injection
The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.smartbear.soapui:soapuito a version that resolves this vulnerability.Fixed in 4.6.4
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1202?
CVE-2014-1202 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2014-1202?
To fix CVE-2014-1202, upgrade to SoapUI version 4.6.4 or later.
What software is affected by CVE-2014-1202?
CVE-2014-1202 affects multiple versions of SoapUI, specifically versions prior to 4.6.4, including 2.5.1, 3.0.1, 3.5, and others.
What are the risks associated with CVE-2014-1202?
The risks associated with CVE-2014-1202 include the potential for unauthorized remote code execution, allowing attackers to execute arbitrary Java code.
Is there a workaround for CVE-2014-1202?
There is no official workaround for CVE-2014-1202; the recommended solution is to upgrade to the latest version.