| [Japanese] | |
JVNDB-2014-000053 | |
JustSystems Online Update Program bundled with JustSystems products vulnerable to arbitrary code execution | |
| Overview | |
"JUST Online Update" and "JUST Online Update for J-License and the management tools" that are bundled with multiple JustSystems products contain a flaw that allows the update program to be executed even if the signature of an update module is invalid. | |
| CVSS Severity (What is CVSS?) | |
|
CVSS V2 Severity:
Base Metrics 7.6 (High) [IPA Score]
| |
| Affected Products | |
All the products that bundle the following update program are affected. | |
JustSystems Corporation | |
A wide range of products are affected. For more information, please refer to the developer's web site. | |
| Impact | |
If a user execute a crafted update module, arbitrary code may be executed. | |
| Solution | |
[Apply the Update] | |
| Vendor Information | |
JustSystems Corporation | |
| CWE (What is CWE?) | |
| |
| CVE (What is CVE?) | |
|
| |
| References | |
| |
| Revision History | |
|
| Date Public | 2014/06/11 |
| Date First Published | 2014/06/11 |
| Date Last Updated | 2014/06/17 |


