CVE-2020-12835

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
20/05/2020
Last modified:
21/07/2021

Description

An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:smartbear:readyapi:3.2.5:*:*:*:*:*:*:*