First published: Thu Nov 13 2003(Updated: )
psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to read arbitrary files via the (1) headername or (2) footername arguments.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle PeopleSoft PeopleTools | =8.15 | |
Oracle PeopleSoft PeopleTools | =8.19 | |
Oracle PeopleSoft PeopleTools | =8.42 | |
Oracle PeopleSoft PeopleTools | =8.43 | |
Oracle PeopleSoft PeopleTools | =8.12 | |
Oracle PeopleSoft PeopleTools | =8.10 | |
Oracle PeopleSoft PeopleTools | =8.17 | |
Oracle PeopleSoft PeopleTools | =8.41 | |
Oracle PeopleSoft PeopleTools | =8.16 | |
Oracle PeopleSoft PeopleTools | =8.13 | |
Oracle PeopleSoft PeopleTools | =8.14 | |
Oracle PeopleSoft PeopleTools | =8.40 | |
Oracle PeopleSoft PeopleTools | =8.18 | |
Oracle PeopleSoft PeopleTools | =8.11 | |
Oracle PeopleSoft PeopleTools | =8.20 | |
Oracle PeopleSoft PeopleTools | =8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0626 is considered to have a moderate security severity due to its potential for unauthorized file access.
To fix CVE-2003-0626, apply the latest security update provided by PeopleSoft for the affected versions of PeopleTools.
CVE-2003-0626 affects PeopleSoft PeopleTools versions 8.4 through 8.43.
CVE-2003-0626 allows remote attackers to read arbitrary files on the server, potentially exposing sensitive information.
As of my last update, CVE-2003-0626 has been publicly disclosed and there is potential for exploitation, thus it is crucial to apply mitigations.