'; } else{ echo ''; } echo '
|
|||
Release Date:2025/9/15
Rule Name:Inspur PS AllotOrderSrv.asmx Remote Code Execution Vulnerability
Severity:critical
CVE ID:
Descripiton:
|
Inspur PS financial management solution includes general ledger management, fixed assets, bill printing, bill management, cost accounting, fund interest calculation, online reimbursement and other financial accounting parts, as well as report management, report summary, financial analysis, cash flow and other analysis reports. The AllotOrderSrv.asmx financial system of Inspur PS has a remote code execution vulnerability, which allows attackers to upload Base64 encoded .net serialization payload, executes arbitrary commands on the server and ultimately controls the server. This rule supports to defend the A6: Vulnerabe and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
Solution:
|
Update vendor patches.