CVE-2023-4528

HIGH

JSCAPE MFT Server <2023.1.9 - Code Injection

Title source: llm
STIX 2.1

Description

Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface

Scores

CVSS v3 7.2
EPSS 0.2707
EPSS Percentile 97.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-502
Status published
Products (1)
redwood/jscape_mft < 2023.1.9
Published Sep 07, 2023
Tracked Since Feb 18, 2026