CVE-2014-1202

critical
Published 2014-01-25 · Modified 2023-12-21
CVSS v3
CVSS v2
9.3
VIR risk
9.3

Description

Code injection via property expansion in SoapUI

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Package impact

EcosystemPackageVulnerableFixed
java Mavencom.smartbear.soapui:soapui<4.6.44.6.4

Application impact

VendorProductVersionsFixed
eviwaresoapui2.5.1
eviwaresoapui3.0.1
eviwaresoapui3.5
eviwaresoapui3.5.1
eviwaresoapui3.6
eviwaresoapui3.6.1
smartbearsoapui{"endIncluding":"4.6.3"}
smartbearsoapui4.0
smartbearsoapui4.0.1
smartbearsoapui4.5
smartbearsoapui4.5.1
smartbearsoapui4.5.2
smartbearsoapui4.6.0
smartbearsoapui4.6.1
smartbearsoapui4.6.2

References

CWEs

CWE-94

Verify integrity in audit chain (admin only). AS-IS.