Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface
References
| Link | Resource |
|---|---|
| https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 | Vendor Advisory |
| https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ | Mitigation Third Party Advisory |
| https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 | Vendor Advisory |
| https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ | Mitigation Third Party Advisory |
Configurations
History
21 Nov 2024, 08:35
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 - Vendor Advisory | |
| References | () https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ - Mitigation, Third Party Advisory |
Information
Published : 2023-09-07 18:15
Updated : 2025-04-23 17:16
NVD link : CVE-2023-4528
Mitre link : CVE-2023-4528
CVE.ORG link : CVE-2023-4528
JSON object : View
Products Affected
redwood
- jscape_mft
CWE
CWE-502
Deserialization of Untrusted Data
