CVE-2023-4528
high · 7.2Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface
7.2
CVSS
31.9%
EPSS (exploit prob.)
98th
EPSS percentile
2023-09-07
Published
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-502
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| redwood | jscape_mft | < 2023.1.9 |
Check a specific version with /api/v1/cve/match.
References
- https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528
- https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/
- https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528
- https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-4528