Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface
References
Link | Resource |
---|---|
https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 | Vendor Advisory |
https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ | Mitigation Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: rapid7
Published: 2023-09-07T17:39:42.355Z
Updated: 2023-09-07T17:39:42.355Z
Reserved: 2023-08-24T20:16:59.319Z
Link: CVE-2023-4528
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-09-07T18:15:07.797
Modified: 2023-09-13T01:02:46.907
Link: CVE-2023-4528
JSON object: View
Redhat Information
No data.
CWE