RULE(RULE ID:338545)

Rule General Information
Release Date: 2024-11-13
Rule Name: ZHENYUN SRM SpEL Expression Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: ZHENYUN SRM cloud platform is developed by Shanghai ZHENYUN Information Technology Co., LTD., a cloud platform designed for the digital transformation of enterprise procurement. ZHENYUN SRM platform has a SpEL expression injection vulnerability. The vulnerability stems from the system's ability to parse the SpEL expression in the post-path of /oauth/public/, so that attackers can use the vulnerability to execute arbitrary code.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.