RULE(RULE ID:338150)

Rule General Information
Release Date: 2024-06-18
Rule Name: Yonyou U9 PatchFile.asmx Arbitrary File Upload Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yonyou U9 is a high-end ERP software designed for medium to large enterprises, offering comprehensive business process management, financial accounting, supply chain management, and other functionalities to support enterprises in achieving refined operations and strategic decision-making. The arbitrary file upload vulnerability in Yoyou U9 allows attackers to upload malicious files, which may lead to remote control of the system, data leakage, or business interruption, posing a severe threat to the enterprise's information security and business stability.
Impact: Attackers can upload viruses, Trojans, WebShell, other malicious scripts or pictures containing scripts to the server, and attackers can use these files for subsequent attacks.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.