RULE(RULE ID:338243)

Rule General Information
Release Date: 2024-07-09
Rule Name: Yonyou U8 Cloud smartweb2.showRPCLoadingTip.d XXE Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yonyou U8 is an integrated enterprise resource planning (ERP) software designed to meet the complex management needs of large and medium-sized enterprises, providing comprehensive financial management, supply chain, production and manufacturing functions. There is an XML external entity injection vulnerability in the Cloud smartweb2. showRPCLoadingTip. d interface of Yonyou U8, which allows attackers to obtain sensitive file information, add malicious content, and attack XML processors containing defects through vulnerable code.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.