CVE-2023-4528
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD
Description
Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface
Affected (1)
Products: Redwood: Jscape Mft
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2023.1.9 |
References (4)
Source: cve@rapid7.com
Vendor Advisory
Source: cve@rapid7.com
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Timeline
No history available yet.