RULE(RULE ID:338477)

Rule General Information
Release Date: 2024-10-22
Rule Name: Yonyou NC word.docx Information Disclosure Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yonyou NC is a high-end enterprise level ERP software launched by Yonyou Company, designed specifically for large enterprises and group enterprises, providing comprehensive core business management functions such as financial management, supply chain management, and human resource management, supporting complex business scenarios and high concurrency data processing needs of enterprises. A sensitive information disclosure vulnerability exists in its word.docx endpoint, which can be exploited by an unauthorized attacker to read server files, resulting in the disclosure of sensitive information.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.