PT-2003-1908 · Oracle · Peoplesoft
Barrett Mcguire
+2
·
Published
2003-10-09
·
Updated
2019-08-19
·
CVE-2003-0841
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PeopleSoft version 8.42
Description
The issue concerns the grid option in PeopleSoft, which stores temporary .xls files in guessable directories under the web document root. This allows remote attackers to steal search results by directly accessing the files via a URL request.
Recommendations
For PeopleSoft version 8.42, consider restricting access to the temporary directories where .xls files are stored to prevent unauthorized access. As a temporary workaround, restrict direct URL access to these files until a more permanent solution is implemented.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Peoplesoft