VulnerabilityModified
CVE-2023-4528
Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface
HIGH 7.2EPSS 31.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 31.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 31.86% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- redwood/jscape mft
- Source
- cve@rapid7.com
References
- https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528Vendor Advisory
- https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/Mitigation, Third Party Advisory
- https://www.jscape.com/blog/binary-management-service-patch-cve-2023-4528Vendor Advisory
- https://www.rapid7.com/blog/post/2023/09/07/cve-2023-4528-java-deserialization-vulnerability-in-jscape-mft-fixed/Mitigation, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.