RULE(RULE ID:338297)

Rule General Information
Release Date: 2024-08-06
Rule Name: Yonyou NC UserAuthenticationServlet Deserialization Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yonyou NC is a high-end enterprise level ERP software launched by Yonyou Company, designed specifically for large enterprises and group enterprises, providing comprehensive core business management functions such as financial management, supply chain management, and human resource management, supporting complex business scenarios and high concurrency data processing needs of enterprises. The UserAuthenticationServlet has a deserialization vulnerability, which attackers can exploit to execute arbitrary commands on the server.
Impact: An attacker can carefully construct malicious serialized data and pass it to the application, and execute the malicious code constructed by the attacker when the application deserializes the object.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.