{"api_version":"1","generated_at":"2026-07-24T19:57:32+00:00","cve":"CVE-2020-12835","urls":{"html":"https://cve.report/CVE-2020-12835","api":"https://cve.report/api/cve/CVE-2020-12835.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-12835","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-12835"},"summary":{"title":"CVE-2020-12835","description":"An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-05-20 13:15:00","updated_at":"2021-07-21 11:39:00"},"problem_types":["CWE-502"],"metrics":[],"references":[{"url":"http://seclists.org/fulldisclosure/2020/May/38","name":"20200519 [SYSS-2019-039] Smartbear ReadyAPI/SoapUI Pro/jProductivity Licensing Unsafe Deserialization","refsource":"FULLDISC","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"Full Disclosure: [SYSS-2019-039] Smartbear ReadyAPI/SoapUI Pro/jProductivity Licensing Unsafe Deserialization","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-039.txt","name":"https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-039.txt","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://www.syss.de/pentest-blog/","name":"https://www.syss.de/pentest-blog/","refsource":"MISC","tags":["Third Party Advisory"],"title":"Pentest Blog – Aktuelle Themen rund um die SySS und ihre Arbeit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/157772/Protection-Licensing-Toolkit-ReadyAPI-3.2.5-Code-Execution-Deserialization.html","name":"http://packetstormsecurity.com/files/157772/Protection-Licensing-Toolkit-ReadyAPI-3.2.5-Code-Execution-Deserialization.html","refsource":"MISC","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Protection Licensing Toolkit ReadyAPI 3.2.5 Code Execution / Deserialization ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-12835","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-12835","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"12835","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"smartbear","cpe5":"readyapi","cpe6":"3.2.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"12835","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"smartbear","cpe5":"readyapi","cpe6":"3.2.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-12835","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.syss.de/pentest-blog/","refsource":"MISC","name":"https://www.syss.de/pentest-blog/"},{"refsource":"FULLDISC","name":"20200519 [SYSS-2019-039] Smartbear ReadyAPI/SoapUI Pro/jProductivity Licensing Unsafe Deserialization","url":"http://seclists.org/fulldisclosure/2020/May/38"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/157772/Protection-Licensing-Toolkit-ReadyAPI-3.2.5-Code-Execution-Deserialization.html","url":"http://packetstormsecurity.com/files/157772/Protection-Licensing-Toolkit-ReadyAPI-3.2.5-Code-Execution-Deserialization.html"},{"refsource":"MISC","name":"https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-039.txt","url":"https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-039.txt"}]}},"nvd":{"publishedDate":"2020-05-20 13:15:00","lastModifiedDate":"2021-07-21 11:39:00","problem_types":["CWE-502"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:smartbear:readyapi:3.2.5:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"12835","Ordinal":"174008","Title":"CVE-2020-12835","CVE":"CVE-2020-12835","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"12835","Ordinal":"1","NoteData":"An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"12835","Ordinal":"2","NoteData":"2020-05-20","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"12835","Ordinal":"3","NoteData":"2020-05-20","Type":"Other","Title":"Modified"}]}}}