CVE-2023-4528

Published Sep 7, 2023

Last updated 5 months ago

Overview

Description
Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface
Source
cve@rapid7.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
7.2
Impact score
5.9
Exploitability score
1.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

cve@rapid7.com
CWE-502
nvd@nist.gov
CWE-502

Social media

Hype score
Not currently trending

Configurations