CVE-2003-0627: Medium severity peoplesoft peopletools vulnerability
Published Dec 31, 2003
·Updated
psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to cause a denial of service (application crash), possibly via the headername and footername arguments.
Affected Software
4 affected components
PeopleSoft PeopleTools=8.42
PeopleSoft PeopleTools=8.43
PeopleSoft PeopleTools=8.41
PeopleSoft PeopleTools=8.40
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Apr 14, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-0627?
CVE-2003-0627 is classified as a denial of service vulnerability that can cause application crashes.
2
How do I fix CVE-2003-0627?
To mitigate CVE-2003-0627, upgrade to a version of PeopleTools that is not vulnerable, specifically versions beyond 8.43.
3
What software is impacted by CVE-2003-0627?
CVE-2003-0627 affects PeopleSoft PeopleTools versions 8.40 to 8.43.
4
How can CVE-2003-0627 be exploited?
CVE-2003-0627 can be exploited by sending specially crafted headername and footername arguments to the psdoccgi.exe.
5
Is there a workaround for CVE-2003-0627?
While there are no official workarounds, limiting access to the vulnerable application may reduce exposure to CVE-2003-0627.