Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface
References
Link | Resource |
---|---|
https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 | Vendor Advisory |
https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ | Mitigation Third Party Advisory |
https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 | Vendor Advisory |
https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ | Mitigation Third Party Advisory |
Configurations
History
21 Nov 2024, 08:35
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 - Vendor Advisory | |
References | () https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ - Mitigation, Third Party Advisory |
13 Sep 2023, 01:02
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ - Mitigation, Third Party Advisory | |
References | (MISC) https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 - Vendor Advisory | |
CPE | cpe:2.3:a:redwood:jscape_mft:*:*:*:*:*:*:*:* | |
First Time |
Redwood
Redwood jscape Mft |
|
CWE | CWE-502 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
07 Sep 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-07 18:15
Updated : 2024-11-21 08:35
NVD link : CVE-2023-4528
Mitre link : CVE-2023-4528
CVE.ORG link : CVE-2023-4528
JSON object : View
Products Affected
redwood
- jscape_mft
CWE
CWE-502
Deserialization of Untrusted Data