cve-2025-34039

CRITICAL CVSS 10.0 opencve
Description

A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet) without proper access controls. The servlet allows unauthenticated remote attackers to execute arbitrary Java code via the bsh.script parameter. This can be exploited to run system commands and ultimately gain full control over the target server. The issue is rooted in a third-party JAR component bundled with the application, and the servlet is accessible without authentication on vulnerable installations. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

Timeline
Published
2025-06-24 02:15 UTC
Last Modified
2026-06-17
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
4.0 10.0 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H mitre
4.0 10.0 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X nvd
4.0 10.0 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H opencve
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "advisories": [
    {
      "id": "EUVD-2025-19039",
      "source": "euvd",
      "title": "A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet) without proper access controls. The servlet allows unauthenticated remote attackers to execute arbitrary Java code via the bsh.script parameter. This can be exploited to run system commands and ultimately gain full control over the target server. The issue is rooted in a third-party JAR component bundled with the application, and the servlet is accessible without authentication on vulnerable installations.",
      "url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-19039"
    }
  ],
  "cve": "CVE-2025-34039",
  "epss": {
    "score": 0.00536
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:yonyou:ufida-nc:*:*:*:*:*:*:*:*"
    ],
    "created": "2025-06-24T01:07:05.619000+00:00",
    "description": "A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet) without proper access controls. The servlet allows unauthenticated remote attackers to execute arbitrary Java code via the bsh.script parameter. This can be exploited to run system commands and ultimately gain full control over the target server. The issue is rooted in a third-party JAR component bundled with the application, and the servlet is accessible without authentication on vulnerable installations. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {
        "score": 10,
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
      }
    },
    "mitre_repo_path": "cves/2025/34xxx/CVE-2025-34039.json",
    "references": [
      "https://vulncheck.com/advisories/yonyou-ufida-nc-beanshell-code-injection",
      "https://www.cnblogs.com/pursue-security/p/17685141.html",
      "https://www.cnvd.org.cn/flaw/show/CNVD-2021-30167"
    ],
    "title": "Yonyou NC BeanShell Command Injection",
    "updated": "2026-05-14T02:07:27.456000+00:00",
    "vendors": [
      "yonyou",
      "yonyou$PRODUCT$ufida-nc"
    ],
    "weaknesses": [
      "CWE-306"
    ]
  },
  "nvd": {
    "cpes": [],
    "created": "2025-06-24T02:15:22.540000+00:00",
    "description": "A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet) without proper access controls. The servlet allows unauthenticated remote attackers to execute arbitrary Java code via the bsh.script parameter. This can be exploited to run system commands and ultimately gain full control over the target server. The issue is rooted in a third-party JAR component bundled with the application, and the servlet is accessible without authentication on vulnerable installations. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {
        "score": 10.0,
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
      }
    },
    "nvd_repo_path": "2025/CVE-2025-34039.json",
    "references": [
      "https://vulncheck.com/advisories/yonyou-ufida-nc-beanshell-code-injection",
      "https://www.cnblogs.com/pursue-security/p/17685141.html",
      "https://www.cnvd.org.cn/flaw/show/CNVD-2021-30167"
    ],
    "title": null,
    "updated": "2026-06-17T09:13:21.470000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-306"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2025-06-24T01:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet) without proper access controls. The servlet allows unauthenticated remote attackers to execute arbitrary Java code via the bsh.script parameter. This can be exploited to run system commands and ultimately gain full control over the target server. The issue is rooted in a third-party JAR component bundled with the application, and the servlet is accessible without authentication on vulnerable installations.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "new": "Yonyou NC BeanShell Command Injection",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-306",
                "CWE-78"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "https://vulncheck.com/advisories/yonyou-ufida-nc-beanshell-code-injection",
                "https://www.cnblogs.com/pursue-security/p/17685141.html",
                "https://www.cnvd.org.cn/flaw/show/CNVD-2021-30167"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV4_0": {
                  "score": 10,
                  "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "ea540927-5e86-436a-a278-ebfb5a61efcf"
      },
      {
        "created": "2025-06-24T16:15:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "yes",
                    "Exploitation": "poc",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "8347f92f-cd4e-413d-89b1-63b4f1cb5734"
      },
      {
        "created": "2025-07-12T13:45:00+00:00",
        "data": [
          {
            "details": {
              "added": {},
              "removed": {},
              "updated": {
                "epss": {
                  "new": {
                    "score": 0.00521
                  },
                  "old": {
                    "score": 0.00407
                  }
                }
              }
            },
            "type": "metrics"
          }
        ],
        "id": "4c42e3a4-0edc-4319-a99a-dcf8f06b5104"
      },
      {
        "created": "2025-11-17T22:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet) without proper access controls. The servlet allows unauthenticated remote attackers to execute arbitrary Java code via the bsh.script parameter. This can be exploited to run system commands and ultimately gain full control over the target server. The issue is rooted in a third-party JAR component bundled with the application, and the servlet is accessible without authentication on vulnerable installations. Exploitation evidence was observed by the Shadowserver Foundation on 2025-07-21 UTC.",
              "old": "A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet) without proper access controls. The servlet allows unauthenticated remote attackers to execute arbitrary Java code via the bsh.script parameter. This can be exploited to run system commands and ultimately gain full control over the target server. The issue is rooted in a third-party JAR component bundled with the application, and the servlet is accessible without authentication on vulnerable installations."
            },
            "type": "description"
          }
        ],
        "id": "92687754-cf30-4365-99b5-d6140259f66b"
      },
      {
        "created": "2025-11-17T22:30:00+00:00",
        "data": [
          {
            "details": {
              "added": [],
              "removed": [
                "CWE-78"
              ]
            },
            "type": "weaknesses"
          }
        ],
        "id": "acce8e0e-9d38-4a77-9936-416a48f40493"
      },
      {
        "created": "2025-11-19T12:15:00+00:00",
        "data": [
          {
            "details": [
              "yonyou",
              "yonyou$PRODUCT$ufida-nc"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:yonyou:ufida-nc:*:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "yonyou",
                "yonyou$PRODUCT$ufida-nc"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "8972bb2a-f64e-48db-84d6-36e645903360"
      },
      {
        "created": "2025-11-20T21:30:00+00:00",
        "data": [
          {
            "details": {
              "new": "A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet) without proper access controls. The servlet allows unauthenticated remote attackers to execute arbitrary Java code via the bsh.script parameter. This can be exploited to run system commands and ultimately gain full control over the target server. The issue is rooted in a third-party JAR component bundled with the application, and the servlet is accessible without authentication on vulnerable installations. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.",
              "old": "A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet) without proper access controls. The servlet allows unauthenticated remote attackers to execute arbitrary Java code via the bsh.script parameter. This can be exploited to run system commands and ultimately gain full control over the target server. The issue is rooted in a third-party JAR component bundled with the application, and the servlet is accessible without authentication on vulnerable installations. Exploitation evidence was observed by the Shadowserver Foundation on 2025-07-21 UTC."
            },
            "type": "description"
          }
        ],
        "id": "08029fb0-910c-4197-a700-c292e9a0c584"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:yonyou:ufida-nc:*:*:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre"
      ]
    },
    "created": {
      "data": "2025-06-24T01:07:05.619000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet) without proper access controls. The servlet allows unauthenticated remote attackers to execute arbitrary Java code via the bsh.script parameter. This can be exploited to run system commands and ultimately gain full control over the target server. The issue is rooted in a third-party JAR component bundled with the application, and the servlet is accessible without authentication on vulnerable installations. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {},
        "provider": null
      },
      "cvssV4_0": {
        "data": {
          "score": 10,
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        "provider": "mitre"
      },
      "epss": {
        "data": {
          "score": 0.00536
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "yes",
            "Exploitation": "poc",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://vulncheck.com/advisories/yonyou-ufida-nc-beanshell-code-injection",
        "https://www.cnblogs.com/pursue-security/p/17685141.html",
        "https://www.cnvd.org.cn/flaw/show/CNVD-2021-30167"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "Yonyou NC BeanShell Command Injection",
      "provider": "mitre"
    },
    "updated": {
      "data": "2026-04-15T00:35:42.020000+00:00",
      "provider": "nvd"
    },
    "vendors": {
      "data": [
        "yonyou",
        "yonyou$PRODUCT$ufida-nc"
      ],
      "providers": [
        "mitre"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-306"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2025-06-24T01:07:05.619000+00:00",
    "description": "A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet) without proper access controls. The servlet allows unauthenticated remote attackers to execute arbitrary Java code via the bsh.script parameter. This can be exploited to run system commands and ultimately gain full control over the target server. The issue is rooted in a third-party JAR component bundled with the application, and the servlet is accessible without authentication on vulnerable installations. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "yes",
          "Exploitation": "poc",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": "Yonyou NC BeanShell Command Injection",
    "updated": "2025-06-24T15:46:46.016000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2025/34xxx/CVE-2025-34039.json",
    "weaknesses": []
  }
}
Enrichment data
View JSON API Download JSON