Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

New CVE Detected

CVE-2022-50973 – Unauthenticated RCE via Arbitrary File Upload – Yonyou KSOA 9.0

Be the first to know when new zero-days emerge:

Summary

CVE-2022-50973 is a critical unauthenticated arbitrary file upload vulnerability in Yonyou KSOA 9.0, affecting the com.sksoft.bill.ImageUpload servlet. By submitting a crafted HTTP POST request with attacker-controlled parameters, a remote, unauthenticated attacker can upload a JSP webshell directly to the web server, resulting in full Remote Code Execution (RCE). The vulnerability carries a CVSS 4.0 score of 9.3 (Critical) and active exploitation in the wild has been confirmed.

Technical details

  • Root cause: The com.sksoft.bill.ImageUpload servlet accepts user-supplied filepath and filename parameters in POST requests with no authentication check, no file type validation, no extension filtering, and no content inspection.
  • Trigger conditions: Any unauthenticated attacker with network access to the KSOA web interface can trigger exploitation by sending a single HTTP POST request.
  • Attack vector: Remote, over the internet; requires no credentials and no user interaction (CVSS: AV:N, PR:N, UI:N).
  • Exploitation technique: An attacker specifies a malicious filename (e.g., a .jsp file containing a webshell) and a target filepath pointing to a server directory. The uploaded file is stored and immediately served as an executable JSP resource by the web server.
  • Impact: Complete compromise of confidentiality, integrity, and availability of the affected host (VC:H/VI:H/VA:H). Active exploitation in the wild was first observed by the Shadowserver Foundation on 2023-11-07 (UTC).

Affected software

  • Yonyou KSOA 9.0

Severity

CVSS v3.1 Base Score: 9.8 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Mitigation and recommended actions

  • No official vendor patch has been identified for CVE-2022-50973 at the time of publication. Organizations should monitor the Yonyou vendor site for security updates.
  • Immediate network-level mitigations:
    • Restrict public internet access to Yonyou KSOA instances; place the application behind a firewall or VPN and limit access to trusted IP ranges only.
    • Block or restrict access to the /servlet/com.sksoft.bill.ImageUpload endpoint at the perimeter (WAF, reverse proxy, or network ACL) if the application cannot be taken offline.
    • Monitor server-side upload directories for unexpected .jsp or script files as an indicator of compromise.
    • Review web server access logs for anomalous POST requests to the ImageUpload servlet path.

IONIX Status

The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

References

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

How IONIX’s External Exposure Management Platform Detects and Validates
Zero-Days to Shrink MTTR

1

Map your entire attack surface (continously)

IONIX uses multi-factor discovery methods, including DNS analysis, certificate mapping, metadata inspection, and more, to automatically map every internet-facing asset across your environment. This includes cloud instances, third-party platforms, shadow IT, and even forgotten infrastructure that traditional tools miss.

2

Monitor for new CVEs

Dozens of threat intel feeds using agentic technology are continuously analyzed to detect the appearance of proof-of-concept code, exploit kits, and indicators of active targeting. IONIX goes further by applying AI to proactively evaluate whether emerging vulnerabilities are likely to be exploited, even before PoCs go public.

3

Identify Potential External Exposures

Not all CVEs matter. IONIX filters vulnerabilities by asking attacker-centric questions: Can it be reached from the internet? Does it require authentication? Is it being exploited in the wild? This dramatically reduces noise and focuses teams on threats that can actually be weaponized.

4

Create Safe, Scalable Exploit Validations

IONIX transforms real-world PoCs into safe, non-intrusive test payloads that can be run in production environments without disruption. These simulations are precisely targeted to the systems that are vulnerable, ensuring rapid validation without unnecessary load.

5

Execute Exploit Validations

By combining context about software stack, versioning, exposure status, and reachability, IONIX ensures that only the right payloads are executed against the right assets, maximizing efficiency and minimizing risk.

6

Drive Fast and Actionable Remediation

Results are routed through integrations with ticketing, SOAR, and SIEM tools. Issues are written in plain language, bundled into remediation clusters, and prioritized based on asset criticality, exploitability, and blast radius. This shortens mean time to remediation (MTTR) and empowers teams to act with confidence.

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge