PT-2003-1369 · Oracle · Peopletools

Published

2003-03-18

·

Updated

2008-09-05

·

CVE-2003-0104

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PeopleTools versions 8.10 through 8.18 PeopleTools version 8.40 PeopleTools version 8.41
Description The issue allows remote attackers to overwrite arbitrary files via the "SchedulerTransfer" servlet. This is a directory traversal vulnerability.
Recommendations For PeopleTools versions 8.10 through 8.18, consider restricting access to the SchedulerTransfer servlet until a patch is available. For PeopleTools version 8.40, consider restricting access to the SchedulerTransfer servlet until a patch is available. For PeopleTools version 8.41, consider restricting access to the SchedulerTransfer servlet until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0104

Affected Products

Peopletools