CVE-2023-4528 is an unsafe deserialization vulnerability affecting JSCAPE MFT Server versions prior to 2023.1.9 across Windows, Linux, and MacOS. This flaw allows a highly privileged attacker to execute arbitrary Java code, including OS commands, through the management interface. Rated 7.2 HIGH on CVSS, it poses a significant risk for complete compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code, active exploitation, or significant community discussion reported for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023.1.9CPE matchmatch criteria | cpe:2.3:a:redwood:jscape_mft:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.