Lucene search

K
cvelistRapid7CVELIST:CVE-2023-0669
HistoryFeb 06, 2023 - 7:16 p.m.

CVE-2023-0669 Fortra GoAnywhere MFT License Response Servlet Command Injection

2023-02-0619:16:19
CWE-502
rapid7
www.cve.org
6
cve-2023-0669
helpsystems
goanywhere mft
command injection
license response servlet
version 7.1.2
vulnerability

AI Score

7.2

Confidence

High

EPSS

0.972

Percentile

99.9%

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Goanywhere MFT",
    "vendor": "Fortra",
    "versions": [
      {
        "lessThanOrEqual": "7.1.1",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]