Security Advisory

CVE-2023-47174

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-10-31 00:00:00
Last updated 2024-09-05 18:01:25
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.