PT-2003-1755 · Oracle · Peoplesoft Peopletools

Published

2003-11-13

·

Updated

2017-07-11

·

CVE-2003-0626

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: PeopleSoft PeopleTools versions 8.4 through 8.43
Description: The issue allows remote attackers to read arbitrary files. This is achieved via the headername or footername arguments.
Recommendations: For PeopleSoft PeopleTools versions 8.4 through 8.43, consider restricting access to the psdoccgi.exe executable until a patch is available. As a temporary workaround, avoid using the headername and footername arguments in the affected API endpoint until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0626

Affected Products

Peoplesoft Peopletools