CVE-2018-20580
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 9.8%
from disclosure to weapon0 days
Published on NVDMay 3
1st PoCMay 3
exploitation probability
9.8%top 5% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.
Affected products
n/a · n/apublic PoCs found — 4
githubgithub.com/gscamelo/CVE-2018-20580★ 2cve_referencepacketstormsecurity.com/files/152731/ReadyAPI-2.5.0-2.6.0-Remote-Code-Execution.htmlunverifiedcve_referencewww.exploit-db.com/exploits/46796/unverifiedexploitdbwww.exploit-db.com/exploits/46796unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.