A deserialization vulnerability in the License Servlet of...
Critical severity
Unreviewed
Published
Sep 19, 2025
to the GitHub Advisory Database
•
Updated Sep 19, 2025
Description
Published by the National Vulnerability Database
Sep 18, 2025
Published to the GitHub Advisory Database
Sep 19, 2025
Last updated
Sep 19, 2025
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
References