RULE(RULE ID:337852)

Rule General Information
Release Date: 2024-03-19
Rule Name: Yonyou U8 Cloud ServiceDispatcher Deserialization Vulnerability -1
Severity:
CVE ID:
Rule Protection Details
Description: Yonyou U8 Cloud is an enterprise level ERP designed to assist enterprises in achieving efficient and digital business collaboration and process management. There is a deserialization vulnerability in the ServiceDispatcher interface in all versions of Yonyou U8Cloud. Attackers can exploit this vulnerability to gain system running privileges.
Impact: An attacker can carefully construct malicious serialized data and pass it to the application, and execute the malicious code constructed by the attacker when the application deserializes the object.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.