'; } else{ echo ''; } echo '
|
|||
Release Date:2025/9/15
Rule Name:Weaver E-Cology v10 H2 Remote Command Exectuion Vulnerability
Severity:critical
CVE ID:
Descripiton:
|
Weaver Ecology10 is a product dedicated to providing comprehensive collaborative management software solutions for enterprises. Through a comprehensive upgrade of its underlying architecture, it achieves high availability, high concurrency, and high-performance technical capabilities. This product adopts a microservice architecture that supports front-end componentization and the splitting and merging of back-end services. It also provides a database multi tenant design, read-write separation, and automated monitoring operation and maintenance platform, ensuring an efficient and smooth system experience and stability. The testConnByBasePassword interface of Weaver 10 has a remote code execution vulnerability, which allows attackers to execute arbitrary JAVA code with administrator privileges to achieve remote code execution. This rule supports to defend the A6: Vulnerabe and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
Solution:
|
Update vendor patches.