Rule Name:Kingdee OA kdsvc Remote command Execution Vulnerability
Severity:critical
CVE ID:
Descripiton:
There is a remote command execution vulnerability in the Kingdee OA. Attackers can send and execute command through /Kingdee.BOS.ServiceFacade.ServiceStub.DevReportService.GetBusinessObjectData.common.kdsvc. such as whoami. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021. Other reference:None