Vulnerability Database

389,860

Total vulnerabilities in the database

CVE-2022-36344 — justsystems / hanako_police_7

Unquoted Search Path or Element

An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.

  • Published: Aug 16, 2022
  • Updated: Sep 25, 2026
  • CVE: CVE-2022-36344
  • Severity: Critical
  • Exploit:
  • CISA KEV:

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CWEs:

Software Affected versions
justsystems / hanako_police_7 All versions
justsystems / hanako_police_6 All versions
justsystems / hanako_police_5 All versions
justsystems / just_smile_7 All versions
justsystems / just_smile_8 All versions
justsystems / just_smile_class_2 All versions
justsystems / just_government_2 All versions
justsystems / just_government_5 All versions
justsystems / just_government_4 All versions
justsystems / homepage_builder_21 All versions
justsystems / homepage_builder_22 All versions
justsystems / just_school_7 All versions
justsystems / just_school_6 All versions
justsystems / homepage_builder_20 All versions
justsystems / shuriken_pro_6 All versions
justsystems / just_pdf_4 All versions
justsystems / just_pdf_3 All versions
justsystems / shuriken_pro_7 All versions
justsystems / just_pdf_5 All versions
justsystems / just_focus_4 All versions
justsystems / just_focus_3 All versions
justsystems / just_note_5 All versions
justsystems / just_note_4 All versions
justsystems / just_note_3 All versions
justsystems / just_calc_5 All versions
justsystems / just_calc_3 All versions
justsystems / just_calc_4 All versions
justsystems / ichitaro_pro_4 All versions
justsystems / ichitaro_pro_5 All versions
justsystems / hanako_pro_3 All versions
justsystems / hanako_pro_4 All versions
justsystems / hanako_pro_5 All versions
justsystems / atok_pro_4 All versions
justsystems / atok_pro_5 All versions
justsystems / atok_medical_2 All versions
justsystems / just_frontier_3 All versions
justsystems / just_smile_6 All versions
justsystems / just_jump_class_2 All versions
justsystems / just_jump_8 All versions
justsystems / just_jump_class All versions
justsystems / tri-de_dataprotect All versions
justsystems / atok_medical_3 All versions
justsystems / atok_pro_3 All versions
justsystems / ichitaro_pro_3 All versions
justsystems / just_medical_4 All versions
justsystems / just_medical_3 All versions
justsystems / just_medical_2 All versions
justsystems / just_medical_5 All versions
justsystems / just_police_4 All versions
justsystems / just_police_3 All versions
justsystems / just_police_2 All versions
justsystems / ichitaro_government_9 All versions
justsystems / ichitaro_government_10 All versions
justsystems / just_police_5 All versions
justsystems / just_government_3 All versions
justsystems / just_office_4 All versions
justsystems / just_office_2 All versions
justsystems / just_office_5 All versions
justsystems / just_office_3 All versions

Frequently Asked Questions

A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.

CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.

A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.

Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.

Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.

SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.