Back to Database
Status published
High
CVE-2018-20580
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0...
Vulnerability Description
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-20580
Credits & Attribution
No credits recorded in the NVD database.
References
More from smartbear
View All →CVE-2021-46708
The swagger-ui-dist package before 4.1.3 for Node.js could allow a...
Medium
6.1
CVE-2021-41657
SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in...
Medium
6.1
CVE-2020-26118
In SmartBear Collaborator Server through 13.3.13302, use of the Google...
High
8.8
CVE-2020-12835
An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5....
Critical
9.8
CVE-2019-17495
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI...
Critical
9.8
Affected Vendor
smartbear
View all reports →Affected Software
readyapi
Vulnerable Versions:
2.5.0, 2.6.0
Timeline
Official Publish:
May 3rd, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.