[Japanese] | |
JVNDB-2014-000053 | |
JustSystems Online Update Program bundled with JustSystems products vulnerable to arbitrary code execution | |
Overview | |
"JUST Online Update" and "JUST Online Update for J-License and the management tools" that are bundled with multiple JustSystems products contain a flaw that allows the update program to be executed even if the signature of an update module is invalid. | |
CVSS Severity (What is CVSS?) | |
CVSS V2 Severity:
Base Metrics 7.6 (High) [IPA Score]
| |
Affected Products | |
All the products that bundle the following update program are affected. | |
JustSystems Corporation | |
A wide range of products are affected. For more information, please refer to the developer's web site. | |
Impact | |
If a user execute a crafted update module, arbitrary code may be executed. | |
Solution | |
[Apply the Update] | |
Vendor Information | |
JustSystems Corporation | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2014/06/11 |
Date First Published | 2014/06/11 |
Date Last Updated | 2014/06/17 |