Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.
为什么是这个 VPI(可解释·实验性)
VPI 计算依据
| 影响度 | 72.00 |
| 利用信号(KEV 收录) | ×1.50 |
| 勒索软件加成 | +5.00 |
| VPI | 100.00 |
VPI 公式 vpi-v1
必要措施
Apply updates per vendor instructions.
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.