CVE-2003-0626: Medium severity PeopleSoft PeopleTools vulnerability
Published Nov 13, 2003
·Updated
psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to read arbitrary files via the (1) headername or (2) footername arguments.
Affected Software
16 affected components
PeopleSoft PeopleTools=8.15
PeopleSoft PeopleTools=8.19
PeopleSoft PeopleTools=8.42
PeopleSoft PeopleTools=8.43
PeopleSoft PeopleTools=8.12
PeopleSoft PeopleTools=8.10
PeopleSoft PeopleTools=8.17
PeopleSoft PeopleTools=8.41
PeopleSoft PeopleTools=8.16
PeopleSoft PeopleTools=8.13
PeopleSoft PeopleTools=8.14
PeopleSoft PeopleTools=8.40
PeopleSoft PeopleTools=8.18
PeopleSoft PeopleTools=8.11
PeopleSoft PeopleTools=8.20
PeopleSoft PeopleTools=8.4
Remediation
Patch Available
Event History
Nov 13, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Apr 14, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-0626?
CVE-2003-0626 is considered to have a moderate security severity due to its potential for unauthorized file access.
2
How do I fix CVE-2003-0626?
To fix CVE-2003-0626, apply the latest security update provided by PeopleSoft for the affected versions of PeopleTools.
3
Which versions of PeopleSoft are affected by CVE-2003-0626?
CVE-2003-0626 affects PeopleSoft PeopleTools versions 8.4 through 8.43.
4
What types of attacks are possible with CVE-2003-0626?
CVE-2003-0626 allows remote attackers to read arbitrary files on the server, potentially exposing sensitive information.
5
Is CVE-2003-0626 being actively exploited?
As of my last update, CVE-2003-0626 has been publicly disclosed and there is potential for exploitation, thus it is crucial to apply mitigations.