Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST request. Attackers can exploit the doAction method, which passes raw HTTP request body data directly to ObjectInputStream.readObject() without filtering, to achieve remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 17:17
Updated : 2026-09-15 18:17
NVD link : CVE-2023-54398
Mitre link : CVE-2023-54398
CVE.ORG link : CVE-2023-54398
JSON object : View
Products Affected
No product.
CWE
CWE-502
Deserialization of Untrusted Data
