FAIL › dossier
yonbip
PRODUCT· dossier confidence 20%
YonBIP is a major Chinese ERP platform with a critical security posture, evidenced by five simultaneous critical vulnerabilities (RCE/SQLi) in version 3_23.05 discovered in January 2024.
PROFILE
CategoryEnterprise ERP SoftwareWhat they doYonBIP is a cloud-based enterprise resource planning (ERP) solution developed by Yonyou, providing supply chain, finance, and HR management capabilities for large enterprises.
Websitehttps://www.yonyou.com ↗
SECURITY POSTURE
Critical vulnerabilities discovered in v3_23.05 within a single day, including multiple RCE and SQLi flaws in core interfaces.
Notable failures
- CVE-2023-51924: RCE via IResourceManager interface
- CVE-2023-51925: RCE via ArcpUploadAction method
- CVE-2023-51906: RCE via ServiceDispatcherServlet
- CVE-2023-51928: RCE via ArcpUploadAction method
- CVE-2023-51927: SQL Injection via AttendScriptController
Patterns: Multiple critical RCE vulnerabilities in v3_23.05; Arbitrary file upload vectors in core task monitoring; SQL injection in HR cloud interfaces
FAILURE HISTORY · 5
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-01-20 | CVE-2023-51924 | critical | An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file. |
| 2024-01-20 | CVE-2023-51925 | critical | An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file. |
| 2024-01-20 | CVE-2023-51906 | critical | An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a crafted script to the ServiceDispatcherServlet uap.framework.rc.itf.IResourceManager component. |
| 2024-01-20 | CVE-2023-51928 | critical | An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file. |
| 2024-01-20 | CVE-2023-51927 | critical | YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScriptController.runScript() method. |
DOSSIER SOURCES
- Latest In Development topics - World of Warcraft Forums · us.forums.blizzard.com
- Drug Shortage Tracker | Medfinder · www.medfinder.com
- Hugging Face Release Notes - July 2026 Latest Updates - Releasebot · releasebot.io
Open questions: Patch availability timeline for v3_23.05 · Current version status post-patch · Impact on existing CMMC Level 2 systems
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 14:12:50.934789+00:00