| [Japanese] | |
| JVNDB-2020-000029 | |
| PALLET CONTROL vulnerable to arbitrary code execution | |
| Overview | |
| PALLET CONTROL provided by JAL Information Technology Co., Ltd. is IT asset management software. PALLET CONTROL contains an arbitrary code execution vulnerability due to improper file access permission (CWE-284). | |
| CVSS Severity (What is CVSS?) | |
| 
  CVSS V3 Severity: Base Metrics 7.8 (High) [IPA Score] 
 
  CVSS V2 Severity: Base Metrics 6.8 (Medium) [IPA Score] 
 | |
| Affected Products | |
|  | |
| JAL Information Technology Co,. Ltd | |
| According to the developer, PalletControl 7 to 9.1 are not affected by this vulnerability. However under the environment where PLS Management Add-on Module is used, all versions are affected. | |
| Impact | |
| A user who can login to the computer where the vulnerable product is installed may execute arbitrary code with SYSTEM privilege. | |
| Solution | |
| [Apply the Patch] | |
| Vendor Information | |
| JAL Information Technology Co,. Ltd | |
| CWE (What is CWE?) | |
| 
 | |
| CVE (What is CVE?) | |
|  | |
| References | |
| 
 | |
| Revision History | |
| 
 | 
| Date Public | 2020/05/11 | 
| Date First Published | 2020/05/11 | 
| Date Last Updated | 2020/05/11 | 


