Description
A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.
References (3)
Scores
CVSS v3
9.8
EPSS
0.0206
EPSS Percentile
84.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-190
CWE-680
Status
published
Products (11)
genivia/gsoap
2.8.107
oracle/communications_diameter_signaling_router
8.0.0 - 8.5.0
oracle/communications_eagle_application_processor
16.1.0 - 16.4.0
oracle/communications_eagle_lnp_application_processor
46.7
oracle/communications_eagle_lnp_application_processor
46.8
oracle/communications_eagle_lnp_application_processor
46.9
oracle/communications_lsms
13.1
oracle/communications_lsms
13.2
oracle/communications_lsms
13.3
oracle/communications_lsms
13.4
... and 1 more
Published
Mar 25, 2021
Tracked Since
Feb 18, 2026