SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-12835

Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol…

CRITICAL 9.8EPSS 13.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 13.0%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
12.97% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-502
Affected
smartbear/readyapi
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.