RULE(RULE ID:338287)

Rule General Information
Release Date: 2024-08-06
Rule Name: Yonyou U9 TransWebService.asmx SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yonyou U9 is an integrated enterprise resource planning (ERP) software designed to provide comprehensive business management solutions for medium and large enterprises to optimize resource allocation, improve operational efficiency and support decision-making. Its TransWebService.asmx interface has a SQL injection vulnerability. Attackers can use the vulnerability to insert malicious SQL code into database queries, which may lead to data disclosure, data corruption, service interruption, and even complete control of the entire database system, posing a serious threat to enterprise data security.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.