CVE-2023-4528

Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface
Configurations

Configuration 1 (hide)

cpe:2.3:a:redwood:jscape_mft:*:*:*:*:*:*:*:*

History

13 Sep 2023, 01:02

Type Values Removed Values Added
References (MISC) https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ - (MISC) https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ - Mitigation, Third Party Advisory
References (MISC) https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 - (MISC) https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 - Vendor Advisory
CPE cpe:2.3:a:redwood:jscape_mft:*:*:*:*:*:*:*:*
First Time Redwood
Redwood jscape Mft
CWE CWE-502
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

07 Sep 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-07 18:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-4528

Mitre link : CVE-2023-4528

CVE.ORG link : CVE-2023-4528


JSON object : View

Products Affected

redwood

  • jscape_mft
CWE
CWE-502

Deserialization of Untrusted Data