Yonyou Vulnerabilities and Affected Products
Vulnerabilities associated with YonBIP.
Products
Clear product- KSOA20 vulnerabilities
- UFIDA ERP-NC4 vulnerabilities
- U8 Cloud2 vulnerabilities
- YonBIP2 vulnerabilities
- UFIDA NC1 vulnerability
- ufida_erp-nc1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-66744HIGH | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing unauthorized access to sensitive information within the system | CVSS7.5v3.1 | EPSS1.45% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2025-3562MEDIUM | Yonyou YonBIP userfile FileInputStream path traversalA vulnerability was found in Yonyou YonBIP MA2.7. It has been declared as problematic. Affected by this vulnerability is the function FileInputStream of the file /mobsm/common/userfile. The manipulation of the argument path leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CWE-22Apr 14, 2025 | CVSS5.3v4.0 | EPSS0.559% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |