Yonyou U8 Cloud Java Deserialization RCE via FileManageServlet
70Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actcvss 9.3epss 0.6%
from disclosure to weapon
Published on NVDSep 15
VulnCheckSep 15
exploitation probability
0.6%top 51% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST request. Attackers can exploit the doAction method, which passes raw HTTP request body data directly to ObjectInputStream.readObject() without filtering, to achieve remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Yonyou · U8 Cloudpublic PoCs found — 2
cve_referenceblog.csdn.net/qq_41904294/article/details/134277353unverifiedcve_referencecn-sec.com/archives/2182384.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://avd.aliyun.com/detail?id=AVD-2023-1686894https://blog.csdn.net/qq_41904294/article/details/134277353https://cn-sec.com/archives/2182384.htmlhttps://security.yonyou.com/#/noticeInfo?id=400https://www.vulncheck.com/advisories/yonyou-u8-cloud-java-deserialization-rce-via-filemanageservlethttps://www.yonyou.com/Global/