Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface
References
Link | Resource |
---|---|
https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 | Vendor Advisory |
https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 | Vendor Advisory |
https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ | Mitigation Third Party Advisory |
https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ | Mitigation Third Party Advisory |
Configurations
History
23 Apr 2025, 17:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-07 18:15
Updated : 2025-04-23 17:16
NVD link : CVE-2023-4528
Mitre link : CVE-2023-4528
JSON object : View
Products Affected
redwood
- jscape_mft
CWE
CWE-502
Deserialization of Untrusted Data