Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface
References
Link | Resource |
---|---|
https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 | Vendor Advisory |
https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ | Mitigation Third Party Advisory |
https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 | Vendor Advisory |
https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ | Mitigation Third Party Advisory |
Configurations
History
21 Nov 2024, 08:35
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-07 18:15
Updated : 2024-11-21 08:35
NVD link : CVE-2023-4528
Mitre link : CVE-2023-4528
CVE.ORG link : CVE-2023-4528
JSON object : View
Products Affected
redwood
- jscape_mft
CWE
CWE-502
Deserialization of Untrusted Data