RULE(RULE ID:338547)

Rule General Information
Release Date: 2024-11-19
Rule Name: Kingdee Apusic Application Serve Unauthorized Directory Traversal Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Kingdee Apusic Application Server is an enterprise level application server that fully supports Jakarta EE technical specifications, providing web containers, EJB containers, and WebService containers. It supports the latest technical specifications and provides key support for the convenient development, flexible deployment, reliable operation, efficient control, and rapid integration of enterprise level applications. It has a directory traversal vulnerability, which unauthorized attackers can exploit to bypass permission checks and read sensitive server files.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.