RULE(RULE ID:339082)

Rule General Information
Release Date: 2025-06-18
Rule Name: Yonyou U8-GRP fastjson Remote Code Execution Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yonyou U8-GRP is a digital management platform designed for government agencies and public institutions, offering integrated solutions for finance, asset management, projects, procurement, etc., to facilitate the informatization and intelligent management of government affairs. Yonyou U8-GRP has a fastjson remote code execution vulnerability. Attackers can exploit this vulnerability to execute arbitrary commands on the server in Base64-encoded format.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.