Lucene search

K
cve[email protected]CVE-2017-2154
HistoryApr 28, 2017 - 4:59 p.m.

CVE-2017-2154

2017-04-2816:59:02
CWE-20
web.nvd.nist.gov
30
vulnerability
untrusted search path
hanako
just
remote attackers
privileges
dll
nvd
cve-2017-2154

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.7%

Untrusted search path vulnerability in Hanako 2017, Hanako 2016, Hanako 2015, Hanako Pro 3, JUST Office 3 [Standard], JUST Office 3 [Eco Print Package], JUST Office 3 & Tri-De DataProtect Package, JUST Government 3, JUST Jump Class 2, JUST Frontier 3, JUST School 6 Premium, Hanako Police 5, JUST Police 3, Hanako 2017 trial version allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

Affected configurations

NVD
Node
justsystemshanakoMatch2015
OR
justsystemshanakoMatch2016
OR
justsystemshanakoMatch2017
OR
justsystemshanakoMatch2017trial_version
OR
justsystemshanako_policeMatch5
OR
justsystemshanako_proMatch3
OR
justsystemsjust_frontierMatch3
OR
justsystemsjust_governmentMatch3
OR
justsystemsjust_jump_classMatch2
OR
justsystemsjust_officeMatch3eco_print_pack
OR
justsystemsjust_officeMatch3standard
OR
justsystemsjust_officeMatch3tri-de_dataprotect_pack
OR
justsystemsjust_policeMatch3
OR
justsystemsjust_schoolMatch6
OR
justsystemsjust_schoolMatch6premium

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.7%

Related for CVE-2017-2154