Yonyou NC BaseApp Deserialization of Untrusted Data Scanner

Targets the BaseApp module's deserialization endpoint, allowing attackers to execute arbitrary code on the server.

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

10 days 17 hours

Scan only one

URL

Toolbox

Yonyou UFIDA NC is a comprehensive enterprise-level management software platform developed by Yonyou. It is widely used by large and medium-sized enterprises to integrate IT solution modeling, development, inheritance, operation, and management. Known for its robust functionalities, Yonyou UFIDA NC supports C/S architecture and utilizes Java programming language. The software allows users to deploy and manage business processes effectively, with interfaces designed for streamlined client-server communication through protocols like HTTP. Enterprises rely on its modules to oversee a range of business operations including financial management, HR, and supply chain activities.

The 'Deserialization of Untrusted Data' vulnerability is a critical security issue that occurs when untrusted data is used to instantiate object streams without validation. This vulnerability allows attackers to manipulate serialized data to inject malicious payloads into the application. Exploitation of such vulnerabilities can enable unauthorized file uploads or command executions on the server. It poses a significant risk as it can be used to perform arbitrary code execution, potentially leading to data breaches or full system compromise.

Specifically, the vulnerability resides in the BaseApp module's deserialization functionality, which processes serialized Java objects from HTTP requests without proper sanitization. Attackers can craft malicious serialized objects targeting the vulnerable endpoint, often found in the /servlet/BaseAppServlet path. By sending a specially crafted payload, they can trigger the deserialization of untrusted data, leading to remote code execution on the server.

If exploited, an attacker can gain complete control over the affected Yonyou UFIDA NC server, allowing them to steal sensitive data, modify business processes, or deploy ransomware. The high CVSS score of 8.0 reflects the severe impact and ease of exploitation. Organizations using this software must prioritize remediation to prevent potential data breaches and operational disruptions.

Get started to protecting your digital assets