CVE-2019-12180: Critical severity smartbear readyapi vulnerability
An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is automatically executed. This allows an attacker to execute arbitrary Groovy Language code (Java scripting language) on the victim machine by inducing it to open a malicious Project. The same issue is present in the "Save Script" function, which is executed automatically when saving a project.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2019-12180.
Which software products are affected by this vulnerability?
SmartBear ReadyAPI versions up to 3.0.0 and SoapUI versions up to 5.5 are affected.
What is the severity level of CVE-2019-12180?
The severity level of CVE-2019-12180 is critical (7.8).
How does the vulnerability in SmartBear ReadyAPI and SoapUI work?
When opening a project, the Groovy "Load Script" is automatically executed, allowing an attacker to execute arbitrary Groovy Language code on the victim machine.
How can I fix this vulnerability in SmartBear ReadyAPI and SoapUI?
Update to a version beyond 3.0.0 for SmartBear ReadyAPI and beyond 5.5 for SoapUI to mitigate this vulnerability.