First published: Fri Feb 07 2003(Updated: )
The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the SimpleFileHandler handler.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle PeopleSoft PeopleTools | =8.15 | |
Oracle PeopleSoft PeopleTools | =8.17 | |
Oracle PeopleSoft PeopleTools | =8.16 | |
Oracle PeopleSoft PeopleTools | =8.14 | |
Oracle PeopleSoft PeopleTools | =8.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2002-1252 is considered to be high due to its potential to allow remote attackers to read arbitrary files.
To fix CVE-2002-1252, upgrade PeopleTools to version 8.19 or later, which contains the necessary security patches.
CVE-2002-1252 affects PeopleTools versions 8.14, 8.15, 8.16, 8.17, and 8.18.
CVE-2002-1252 can lead to unauthorized access to sensitive files on the server, potentially compromising data integrity and confidentiality.
Mitigation options for CVE-2002-1252 may include disabling XML External Entities processing, but upgrading is the recommended solution.