Impact
Yonyou U8 Cloud contains an unauthenticated Java deserialization flaw in the FileManageServlet component. Attackers can send a crafted POST request that is read directly by ObjectInputStream.readObject(), allowing arbitrary OS command execution. The vulnerability bypasses authentication and permits full control of the affected server, compromising confidentiality, integrity, and availability. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.
Affected Systems
The vulnerability affects the Yonyou U8 Cloud product offered by Yonyou. No specific version is indicated in the CNA data, so all deployed instances of Yonyou U8 Cloud, regardless of patch level, may be susceptible unless they have applied the vendor's patch.
Risk and Exploitability
The CVSS score for this vulnerability is 9.3, indicating critical severity and a high potential impact. The EPSS score is < 1%, suggesting a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but that does not diminish its risk. Attackers can exploit the unfiltered ObjectInputStream.readObject() call by sending a crafted POST request to the FileManageServlet endpoint over the network, bypassing authentication and enabling remote command execution. The lack of authentication and the direct deserialization make the attack vector straightforward and highly plausible for a motivated adversary.
OpenCVE Enrichment