Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2022-50973 -- CVSS 9.8 Vulnerability Briefing

CVE-2022-50973 | CVSS 9.8 (Critical) | Exploit: No known exploit

What Is It

CVE-2022-50973 is an unauthenticated arbitrary file upload vulnerability in Yonyou KSOA 9.0, specifically within the com.sksoft.bill.ImageUpload servlet component.

Technical Detail

The flaw exists in the ImageUpload servlet, which fails to enforce authentication or adequate file type validation before accepting uploaded content. An unauthenticated remote attacker can submit a crafted HTTP request to the servlet endpoint to upload arbitrary files, including server-side executable code, to the target system. Successful exploitation can result in remote code execution (RCE) under the privileges of the application server process, leading to full system compromise.

Exploitation Status

No known exploit code has been publicly documented or confirmed at this time. This vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The exploit maturity is currently assessed as no known exploit, though the unauthenticated nature of the attack surface and the critical CVSS score of 9.8 make this a high-priority candidate for future exploitation attempts.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this vulnerability in available intelligence sources.

What To Do

Organizations running Yonyou KSOA 9.0 should apply any available vendor-supplied patches immediately, prioritizing this as a critical-severity item given the unauthenticated attack vector and potential for RCE. If a patch is not yet available or cannot be applied immediately, restrict network access to the KSOA application server so that the ImageUpload servlet endpoint is not reachable from untrusted networks or the public internet. Web application firewall rules should be configured to block or alert on unexpected multipart file upload requests to the affected servlet path. Monitor application and web server logs for anomalous POST requests targeting the com.sksoft.bill.ImageUpload endpoint, and audit the server's upload directories for unexpected or executable file types. Contact Yonyou directly to confirm patch availability and remediation guidance specific to your deployment version.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →