CVE Database
/

CVE-2023-0669

Back to search

CVE-2023-0669

Published: Feb 6, 2023

Modified: Oct 21, 2025

PUBLISHED

Description

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

VendorProductVersions

Fortra

Goanywhere MFT

affected
0 - <= 7.1.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now