First published: Wed Dec 31 2003(Updated: )
psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to cause a denial of service (application crash), possibly via the headername and footername arguments.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle PeopleSoft PeopleTools | =8.42 | |
Oracle PeopleSoft PeopleTools | =8.43 | |
Oracle PeopleSoft PeopleTools | =8.41 | |
Oracle PeopleSoft PeopleTools | =8.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0627 is classified as a denial of service vulnerability that can cause application crashes.
To mitigate CVE-2003-0627, upgrade to a version of PeopleTools that is not vulnerable, specifically versions beyond 8.43.
CVE-2003-0627 affects PeopleSoft PeopleTools versions 8.40 to 8.43.
CVE-2003-0627 can be exploited by sending specially crafted headername and footername arguments to the psdoccgi.exe.
While there are no official workarounds, limiting access to the vulnerable application may reduce exposure to CVE-2003-0627.