VYPR
High severity7.8NVD Advisory· Published Feb 19, 2018· Updated Jun 17, 2026

CVE-2017-16670

CVE-2017-16670

Description

The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.

Affected products

3
  • Smartbear/Soapuiinferred2 versions
    =5.3.0+ 1 more
    • (no CPE)range: =5.3.0
    • cpe:2.3:a:smartbear:soapui:5.3.0:*:*:*:*:*:*:*
  • SoapUI/SoapUIllm-create
    Range: =5.3.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.