peter bassill · operator
$ cve CVE-2020-12835 JSON

CVE-2020-12835

9.8
CRITICAL · CVSS 3.1 · EPSS 13% (pctl 96)

Patch early

EPSS 13% — above the 10% action threshold.

Description

An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS12.97% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2020-05-20
Last modified2026-06-17

Affected (1)

VendorProduct
smartbearreadyapi

References

→ the Explorer  ·  watch your stack  ·  NVD