CVE-2022-36344

An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:justsystems:atok_medical_2:*:*:*:*:*:windows:*:*
cpe:2.3:a:justsystems:atok_medical_3:*:*:*:*:*:windows:*:*
cpe:2.3:a:justsystems:atok_pro_3:*:*:*:*:*:windows:*:*
cpe:2.3:a:justsystems:atok_pro_4:*:*:*:*:*:windows:*:*
cpe:2.3:a:justsystems:atok_pro_5:*:*:*:*:*:windows:*:*
cpe:2.3:a:justsystems:hanako_police_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:hanako_police_6:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:hanako_police_7:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:hanako_pro_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:hanako_pro_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:hanako_pro_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:homepage_builder_20:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:homepage_builder_21:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:homepage_builder_22:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_government_10:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_government_8:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_government_9:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_pro_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_pro_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_pro_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_calc_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_calc_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_calc_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_focus_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_focus_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_frontier_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_government_2:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_government_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_government_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_government_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_jump_8:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_jump_class:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_jump_class_2:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_medical_2:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_medical_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_medical_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_medical_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_note_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_note_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_note_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_office_2:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_office_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_office_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_office_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_pdf_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_pdf_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_pdf_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_pdf_5:*:*:*:*:pro:*:*:*
cpe:2.3:a:justsystems:just_police_2:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_police_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_police_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_police_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_school_6:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_school_7:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_smile_6:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_smile_7:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_smile_8:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_smile_class_2:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:shuriken_pro_6:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:shuriken_pro_7:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:tri-de_dataprotect:*:*:*:*:*:*:*:*

History

23 Aug 2022, 16:02

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References (MISC) https://jvn.jp/en/jp/JVN57073973/index.html - (MISC) https://jvn.jp/en/jp/JVN57073973/index.html - Third Party Advisory
References (MISC) https://www.justsystems.com/jp/corporate/info/js22001.html - (MISC) https://www.justsystems.com/jp/corporate/info/js22001.html - Vendor Advisory
First Time Justsystems just Jump 8
Justsystems just Smile 6
Justsystems just Smile 8
Justsystems just School 7
Justsystems just Medical 4
Justsystems just Jump Class
Justsystems just Smile 7
Justsystems hanako Police 5
Justsystems just Focus 4
Justsystems just School 6
Justsystems just Office 4
Justsystems just Note 3
Justsystems atok Pro 4
Justsystems just Calc 4
Justsystems just Government 5
Justsystems just Calc 5
Justsystems just Note 5
Justsystems just Office 2
Justsystems atok Medical 2
Justsystems just Police 5
Justsystems hanako Pro 5
Justsystems ichitaro Pro 3
Justsystems just Government 3
Justsystems just Calc 3
Justsystems tri-de Dataprotect
Justsystems just Medical 3
Justsystems shuriken Pro 7
Justsystems ichitaro Pro 5
Justsystems just Police 2
Justsystems just Pdf 3
Justsystems just Pdf 4
Justsystems just Office 5
Justsystems homepage Builder 21
Justsystems atok Medical 3
Justsystems ichitaro Government 8
Justsystems atok Pro 5
Justsystems just Government 4
Justsystems hanako Police 7
Justsystems
Justsystems hanako Pro 4
Justsystems ichitaro Pro 4
Justsystems just Note 4
Justsystems homepage Builder 22
Justsystems just Medical 2
Justsystems just Police 4
Justsystems just Medical 5
Justsystems ichitaro Government 9
Justsystems homepage Builder 20
Justsystems just Smile Class 2
Justsystems just Police 3
Justsystems hanako Pro 3
Justsystems just Office 3
Justsystems atok Pro 3
Justsystems just Focus 3
Justsystems just Frontier 3
Justsystems just Pdf 5
Justsystems just Government 2
Justsystems just Jump Class 2
Justsystems shuriken Pro 6
Justsystems ichitaro Government 10
Justsystems hanako Police 6
CPE cpe:2.3:a:justsystems:just_government_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:hanako_pro_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_pro_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_government_10:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_medical_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_frontier_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_school_7:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_pdf_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_government_8:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_government_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_calc_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_calc_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:atok_pro_4:*:*:*:*:*:windows:*:*
cpe:2.3:a:justsystems:just_police_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_police_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:homepage_builder_20:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_pro_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_calc_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_jump_class:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_pdf_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_smile_6:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:hanako_pro_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_medical_2:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_government_9:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_note_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_jump_class_2:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_police_2:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:hanako_pro_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_pro_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_pdf_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:atok_medical_2:*:*:*:*:*:windows:*:*
cpe:2.3:a:justsystems:hanako_police_6:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:atok_medical_3:*:*:*:*:*:windows:*:*
cpe:2.3:a:justsystems:just_office_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_school_6:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_focus_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_government_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:tri-de_dataprotect:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_medical_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_smile_class_2:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_office_2:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_jump_8:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_police_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:hanako_police_7:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:atok_pro_5:*:*:*:*:*:windows:*:*
cpe:2.3:a:justsystems:homepage_builder_22:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:homepage_builder_21:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_smile_7:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_medical_3:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:shuriken_pro_7:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_government_2:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_note_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:shuriken_pro_6:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:hanako_police_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:atok_pro_3:*:*:*:*:*:windows:*:*
cpe:2.3:a:justsystems:just_office_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_smile_8:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_pdf_5:*:*:*:*:pro:*:*:*
cpe:2.3:a:justsystems:just_note_5:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_focus_4:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_office_3:*:*:*:*:*:*:*:*
CWE CWE-428

16 Aug 2022, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-16 08:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-36344

Mitre link : CVE-2022-36344

CVE.ORG link : CVE-2022-36344


JSON object : View

Products Affected

justsystems

  • just_note_4
  • homepage_builder_22
  • ichitaro_government_9
  • just_office_5
  • atok_pro_5
  • just_medical_3
  • atok_pro_4
  • just_medical_5
  • just_note_3
  • just_government_3
  • just_police_4
  • hanako_pro_3
  • just_calc_3
  • just_jump_8
  • ichitaro_pro_3
  • ichitaro_pro_4
  • just_focus_4
  • just_jump_class_2
  • just_school_7
  • hanako_police_6
  • shuriken_pro_7
  • just_government_4
  • ichitaro_pro_5
  • shuriken_pro_6
  • just_smile_8
  • just_calc_4
  • atok_medical_3
  • hanako_pro_5
  • just_focus_3
  • hanako_pro_4
  • hanako_police_7
  • homepage_builder_21
  • ichitaro_government_10
  • just_office_4
  • just_pdf_3
  • just_pdf_4
  • just_police_3
  • just_police_2
  • hanako_police_5
  • just_pdf_5
  • just_smile_7
  • atok_medical_2
  • just_government_5
  • just_jump_class
  • just_smile_class_2
  • atok_pro_3
  • just_smile_6
  • just_medical_4
  • just_government_2
  • just_office_3
  • just_calc_5
  • just_note_5
  • just_school_6
  • homepage_builder_20
  • just_frontier_3
  • tri-de_dataprotect
  • just_medical_2
  • ichitaro_government_8
  • just_office_2
  • just_police_5
CWE
CWE-428

Unquoted Search Path or Element