References https://www.veeam.com/kb4679 https://www.veeam.com/kb4575 https://www.venustech.com.cn/new_type/aqtg/20241204/28159.html https://avd.aliyun.com/detail?id=AVD-2024-38651 https://www.anquanke.com/post/id/302476 https://thehackernews.com/2024/12/veeam-issues-patch-for-critical-rce.html https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-rce-bug-in-service-provider-console/ https://nvd.nist.gov/vuln/detail/CVE-2024-42448 https://nvd.nist.gov/vuln/detail/CVE-2024-29212 https://www.tenable.com/plugins/nessus/212091
Related Vulnerabilities畅捷通 T+ POSSyncService.asmx 接口SQL注入漏洞Juggle /h2-console 命令执行漏洞(CVE-2026-67208)PoCmonitorr-file-upload: Monitorr Services Configuration - Arbitrary File UploadPoCCVE-2026-67208: Juggle <= 1.6.0 - Unauthenticated Exposed H2 Database ConsoleServiceNow-AI-Platform /assessment_thanks.do 代码执行漏洞(CVE-2026-6875)PoCCVE-2026-59801: 9Router - Unauthenticated LLM Provider API ExposurePoCCVE-2026-6875: ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCE金蝶EAS /ormrpc/services/BSHService 代码执行漏洞用友U8Cloud /ServiceDispatcherServlet 文件上传漏洞用友 U8cloud /service/XChangeServlet SQL 注入漏洞关于NC系统BapAnaRepDefService的sql注入漏洞的安全通告时空智友ERP系统 /formservice updater.uploadStudioFile 文件上传漏洞广联达OA /Mail/Services/EmailAccountOrgUserService.asmx/GetUserEmailByOrgEmails XML 外部实体注入漏洞