First published: Tue Nov 18 2003(Updated: )
PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI) files via an HTTP request with an invalid value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle PeopleSoft PeopleTools | =8.15 | |
Oracle PeopleSoft PeopleTools | =8.19 | |
Oracle PeopleSoft PeopleTools | =8.42 | |
Oracle PeopleSoft PeopleTools | =8.43 | |
Oracle PeopleSoft PeopleTools | =8.12 | |
Oracle PeopleSoft PeopleTools | =8.10 | |
Oracle PeopleSoft PeopleTools | =8.17 | |
Oracle PeopleSoft PeopleTools | =8.41 | |
Oracle PeopleSoft PeopleTools | =8.16 | |
Oracle PeopleSoft PeopleTools | =8.11 | |
Oracle PeopleSoft PeopleTools | =8.18 | |
Oracle PeopleSoft PeopleTools | =8.13 | |
Oracle PeopleSoft PeopleTools | =8.20 | |
Oracle PeopleSoft PeopleTools | =8.4 | |
Oracle PeopleSoft PeopleTools | =8.14 | |
Oracle PeopleSoft PeopleTools | =8.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0628 is rated as a medium severity vulnerability.
To fix CVE-2003-0628, upgrade to a version of PeopleTools later than 8.43.
CVE-2003-0628 affects PeopleTools versions 8.10 through 8.43.
CVE-2003-0628 is a path disclosure vulnerability in the PeopleSoft Gateway Administration servlet.
Exploiting CVE-2003-0628 allows attackers to obtain the full pathnames for server-side include (SSI) files.