A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
References
Configurations
No configuration.
History
18 Sep 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
18 Sep 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-18 22:15
Updated : 2025-09-19 16:00
NVD link : CVE-2025-10035
Mitre link : CVE-2025-10035
CVE.ORG link : CVE-2025-10035
JSON object : View
Products Affected
No product.