CVE-2017-2154 Details
Description
Untrusted search path vulnerability in Hanako 2017, Hanako 2016, Hanako 2015, Hanako Pro 3, JUST Office 3 [Standard], JUST Office 3 [Eco Print Package], JUST Office 3 & Tri-De DataProtect Package, JUST Government 3, JUST Jump Class 2, JUST Frontier 3, JUST School 6 Premium, Hanako Police 5, JUST Police 3, Hanako 2017 trial version allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN54268888/index.html | CVE | Third Party AdvisoryVDB Entry |
| https://www.justsystems.com/jp/info/js17002.html | CVE | Vendor Advisory |
| https://jvn.jp/en/jp/JVN54268888/index.html | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.justsystems.com/jp/info/js17002.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| justsystems hanako | 2015 2016 2017 |
CPE
Remediation
| |
| justsystems hanako police | 5 |
CPE
Remediation
| |
| justsystems hanako pro | 3 |
CPE
Remediation
| |
| justsystems just frontier | 3 |
CPE
Remediation
| |
| justsystems just government | 3 |
CPE
Remediation
| |
| justsystems just jump class | 2 |
CPE
Remediation
| |
| justsystems just office | 3 |
CPE
Remediation
| |
| justsystems just police | 3 |
CPE
Remediation
| |
| justsystems just school | 6 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| May 12, 2017 | CVE Modified | [email protected] |
| May 5, 2017 | Initial Analysis | [email protected] |