PT-2003-1755 · Oracle · Peoplesoft Peopletools
Published
2003-11-13
·
Updated
2017-07-11
·
CVE-2003-0626
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
PeopleSoft PeopleTools versions 8.4 through 8.43
Description:
The issue allows remote attackers to read arbitrary files. This is achieved via the
headername or footername arguments.Recommendations:
For PeopleSoft PeopleTools versions 8.4 through 8.43, consider restricting access to the
psdoccgi.exe executable until a patch is available. As a temporary workaround, avoid using the headername and footername arguments in the affected API endpoint until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Peoplesoft Peopletools