Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface
References
Link | Resource |
---|---|
https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 | Vendor Advisory |
https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ | Mitigation Third Party Advisory |
https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 | Vendor Advisory |
https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ | Mitigation Third Party Advisory |
Configurations
History
21 Nov 2024, 08:35
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 - Vendor Advisory | |
References | () https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ - Mitigation, Third Party Advisory |
13 Sep 2023, 01:02
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-502 | |
First Time |
Redwood jscape Mft
Redwood |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
References | (MISC) https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528 - Vendor Advisory | |
References | (MISC) https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/ - Mitigation, Third Party Advisory | |
CPE | cpe:2.3:a:redwood:jscape_mft:*:*:*:*:*:*:*:* |
07 Sep 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-07 18:15
Updated : 2025-04-23 17:16
NVD link : CVE-2023-4528
Mitre link : CVE-2023-4528
CVE.ORG link : CVE-2023-4528
JSON object : View
Products Affected
redwood
- jscape_mft
CWE
CWE-502
Deserialization of Untrusted Data