1. Symantec-Broadcom-Horizontal/
  2. Security Response/
  3. Attack Signatures/
  4. Attack: SmartBear ReadyAPI CVE-2018-20580

Attack: SmartBear ReadyAPI CVE-2018-20580

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects the attempt to execute arbitrary code within the context of the user running the affected application. Failed exploit attempts will result in a denial-of-service condition.

Additional Information

The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.

Affected

  • SmartBear ReadyAPI 2.5.0 and 2.6.0

Response


  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube