Unrated severityNVD Advisory· Published May 20, 2020· Updated Aug 4, 2024
CVE-2020-12835
CVE-2020-12835
Description
An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- SmartBear/ReadyAPI SoapUI Prodescription
- Range: <=3.2.5
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/157772/Protection-Licensing-Toolkit-ReadyAPI-3.2.5-Code-Execution-Deserialization.htmlmitrex_refsource_MISC
- seclists.org/fulldisclosure/2020/May/38mitremailing-listx_refsource_FULLDISC
- www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-039.txtmitrex_refsource_MISC
- www.syss.de/pentest-blog/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.