RULE(RULE ID:339205)

Rule General Information
Release Date: 2025-06-25
Rule Name: Yonyou GRPA++ Cloud Arbitrary File Read Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yoniu GRP-A++Cloud Government Financial Cloud Product is developed based on government accounting standards and integrated budget management specifications. It serves government administrative institutions, implements national innovation and internal control standard requirements for administrative institutions, supports provincial-level centralized deployment as well as internal and external business collaboration. By building cloud-native services, it supports continuous business evolution and transformation, providing integrated government business and finance services, standardized financial processes, automation, and intelligent services. It creates a secure, reliable, and controllable information operation environment to enhance the digital governance capabilities of various units. The /ma/emp/maEmp/download interface in Yoniu GRP-A++Cloud is vulnerable to arbitrary file reading. Attackers can craft malicious requests to read sensitive files on the server, leading to the disclosure of sensitive information.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.