PT-2003-1908 · Oracle · Peoplesoft

Barrett Mcguire

+2

·

Publicado

2003-10-09

·

Atualizado

2019-08-19

·

CVE-2003-0841

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PeopleSoft version 8.42
Description The issue concerns the grid option in PeopleSoft, which stores temporary .xls files in guessable directories under the web document root. This allows remote attackers to steal search results by directly accessing the files via a URL request.
Recommendations For PeopleSoft version 8.42, consider restricting access to the temporary directories where .xls files are stored to prevent unauthorized access. As a temporary workaround, restrict direct URL access to these files until a more permanent solution is implemented.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0841

Produtos afetados

Peoplesoft