RULE(RULE ID:339079)

Rule General Information
Release Date: 2025-06-18
Rule Name: Yonyou NC PortalSESInitToolService Sensitive Infomation Leakage Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yonyou NC is a high-end ERP system designed for large enterprises, supporting core functions such as group control, financial sharing, and supply chain collaboration, helping enterprises achieve digital transformation. There is a sensitive information leakage vulnerability in the PortalSESInitToolService of Yonyou NC. Attackers can exploit this vulnerability to obtain database usernames and passwords.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.