soapui icon indicating copy to clipboard operation
soapui copied to clipboard

SOAP UI malforms Request Body

Open onetr1ck opened this issue 1 year ago • 0 comments

Given data with these special characters (in this order) "${" (without quotes) the sent Request Body is malformed. This is also true for strings like "abc$fghi{jklm" if there are not "enough" uncritical characters between the above mentioned characters. This can be recorded with wireshark or tcpdump. Tested Versions: 5.7.0 and 5.6.1 (both affected)

Given request:

<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:web="myURL">
   <soapenv:Header/>
   <soapenv:Body>
      <web:MyList>
         <web:cmdHeader>
            <id>?</id>
            <uuid>?</uuid>
            <creationDateTime>?</creationDateTime>
            <senderBusinessSystemID>?</senderBusinessSystemID>
         </web:cmdHeader>
         <!--1 or more repetitions:-->
         <ListItem>
            <myItemXYZ>aaaaaa${bbbbbb</myItemXYZ>
         </ListItem>
      </web:MyList>
   </soapenv:Body>
</soapenv:Envelope>

Output request (recorded with wireshark):

<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:web="myURL">
   <soapenv:Header/>
   <soapenv:Body>
      <web:MyList>
         <web:cmdHeader>
            <id>?</id>
            <uuid>?</uuid>
            <creationDateTime>?</creationDateTime>
            <senderBusinessSystemID>?</senderBusinessSystemID>
         </web:cmdHeader>
         <!--1 or more repetitions:-->
         <ListItem>
            <myItemXYZ>aaaaaa<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:web="myURL">
   <soapenv:Header/>
   <soapenv:Body>
      <web:MyList>
         <web:cmdHeader>
            <id>?</id>
            <uuid>?</uuid>
            <creationDateTime>?</creationDateTime>
            <senderBusinessSystemID>?</senderBusinessSystemID>
         </web:cmdHeader>
         <!--1 or more repetitions:-->
         <ListItem>
            <myItemXYZ>aaaaaa${bbbbbb</myItemXYZ>
         </ListItem>
      </web:MyList>
   </soapenv:Body>
</soapenv:Envelope>

onetr1ck avatar May 04 '23 13:05 onetr1ck