RULE(RULE ID:339144)

Rule General Information
Release Date: 2025-06-25
Rule Name: Yonyou ServiceDispatcherServlet Deserialization Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yonyou NC is a high-end enterprise-level ERP software launched by Yonyou, specifically designed for large enterprises and corporate groups. It provides comprehensive core business management functions including financial management, supply chain management, and human resource management, supporting complex business scenarios and high-concurrency data processing requirements. The Yonyou NC ServiceDispatcherServlet contains a deserialization vulnerability, which allows attackers to send maliciously crafted serialized data to execute remote code and gain control over the server.
Impact: An attacker can carefully construct malicious serialized data and pass it to the application, and execute the malicious code constructed by the attacker when the application deserializes the object.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.