CVE-2017-16670: Code Injection
Published Feb 19, 2018
·Updated
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.
Affected Software
1 affected component
SMARTBEAR SoapUI=5.3.0
Event History
Feb 19, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-16670.
2
What is the severity of CVE-2017-16670?
The severity of CVE-2017-16670 is high with a CVSS score of 7.8.
3
What is affected by CVE-2017-16670?
SoapUI version 5.3.0 is affected by CVE-2017-16670.
4
How can remote attackers exploit CVE-2017-16670?
Remote attackers can exploit CVE-2017-16670 by executing arbitrary Java code via a crafted request parameter in a WSDL project file.
5
Are there any known fixes for CVE-2017-16670?
There is no known fix for CVE-2017-16670 at the moment.