CVE-2002-1252: Medium severity PeopleSoft PeopleTools vulnerability
The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the SimpleFileHandler handler.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1252?
The severity of CVE-2002-1252 is considered to be high due to its potential to allow remote attackers to read arbitrary files.
How do I fix CVE-2002-1252?
To fix CVE-2002-1252, upgrade PeopleTools to version 8.19 or later, which contains the necessary security patches.
What software versions are affected by CVE-2002-1252?
CVE-2002-1252 affects PeopleTools versions 8.14, 8.15, 8.16, 8.17, and 8.18.
What is the impact of CVE-2002-1252 on affected systems?
CVE-2002-1252 can lead to unauthorized access to sensitive files on the server, potentially compromising data integrity and confidentiality.
Is there a way to mitigate CVE-2002-1252 without upgrading?
Mitigation options for CVE-2002-1252 may include disabling XML External Entities processing, but upgrading is the recommended solution.