FAIL › dossier
yonyou
VENDOR· dossier confidence 40%
Yonyou is a public Chinese enterprise software vendor with a critical security track record, evidenced by five critical RCE and SQL injection vulnerabilities in the YonBIP v3_23.05 release.
PROFILE
CategoryEnterprise Software VendorWhat they doYonyou Network Technology Co., Ltd. is a Chinese public company specializing in enterprise resource planning (ERP) and business management software, including the YonBIP and NC Cloud platforms.Ownershippublic
Websitehttps://www.yonyou.com ↗
SECURITY POSTURE
High-risk vendor with a critical concentration of RCE vulnerabilities in the YonBIP v3_23.05 release, indicating a failure to patch known vulnerabilities across multiple interfaces within a single version.
Notable failures
- CVE-2023-51924: RCE via IResourceManager interface
- CVE-2023-51925: RCE via ArcpUploadAction.doAction()
- CVE-2023-51906: RCE via ServiceDispatcherServlet
- CVE-2023-51928: RCE via ArcpUploadAction.doAction()
- CVE-2023-51927: SQL Injection via AttendScriptController
Patterns: Multiple critical RCE vulnerabilities in YonBIP v3_23.05; Arbitrary file upload vectors enabling code execution; SQL injection in HR/attendance modules
FAILURE HISTORY · 5
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-01-20 | CVE-2023-51924 | critical | An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file. |
| 2024-01-20 | CVE-2023-51925 | critical | An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file. |
| 2024-01-20 | CVE-2023-51906 | critical | An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a crafted script to the ServiceDispatcherServlet uap.framework.rc.itf.IResourceManager component. |
| 2024-01-20 | CVE-2023-51928 | critical | An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file. |
| 2024-01-20 | CVE-2023-51927 | critical | YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScriptController.runScript() method. |
DOSSIER SOURCES
- 用友网络 9.43 (0.75%)_公司简介_新浪财经_新浪网 - sina · money.finance.sina.com.cn
- Yonyou Network Technology (SHA:600588) Stock Price & Overview · stockanalysis.com
- 产品知识地图全集 - c2.yonyoucloud.com · c2.yonyoucloud.com
- Latest In Development topics - World of Warcraft Forums · us.forums.blizzard.com
- YonBIP V3.0高级版产品上市调价补丁说明.pdf-原创力文档 · max.book118.com
Open questions: Patch status of YonBIP v3_23.05 · Current exploitation status of CVE-2023-51924 through 51928
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 14:14:31.956029+00:00