Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface
References
| Link | Resource |
|---|---|
| https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 | Vendor Advisory |
| https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ | Mitigation Third Party Advisory |
| https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 | Vendor Advisory |
| https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ | Mitigation Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-09-07 18:15
Updated : 2025-04-23 17:16
NVD link : CVE-2023-4528
Mitre link : CVE-2023-4528
CVE.ORG link : CVE-2023-4528
JSON object : View
Products Affected
redwood
- jscape_mft
CWE
CWE-502
Deserialization of Untrusted Data
