CVE-2003-0628: Medium severity PeopleSoft PeopleTools vulnerability
Published Nov 18, 2003
·Updated
PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI) files via an HTTP request with an invalid value.
Affected Software
16 affected components
PeopleSoft PeopleTools=8.15
PeopleSoft PeopleTools=8.19
PeopleSoft PeopleTools=8.42
PeopleSoft PeopleTools=8.43
PeopleSoft PeopleTools=8.12
PeopleSoft PeopleTools=8.10
PeopleSoft PeopleTools=8.17
PeopleSoft PeopleTools=8.41
PeopleSoft PeopleTools=8.16
PeopleSoft PeopleTools=8.11
PeopleSoft PeopleTools=8.18
PeopleSoft PeopleTools=8.13
PeopleSoft PeopleTools=8.20
PeopleSoft PeopleTools=8.4
PeopleSoft PeopleTools=8.14
PeopleSoft PeopleTools=8.40
Event History
Nov 18, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Dec 15, 2003
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0628?
CVE-2003-0628 is rated as a medium severity vulnerability.
2
How do I fix CVE-2003-0628?
To fix CVE-2003-0628, upgrade to a version of PeopleTools later than 8.43.
3
What systems are affected by CVE-2003-0628?
CVE-2003-0628 affects PeopleTools versions 8.10 through 8.43.
4
What type of vulnerability is CVE-2003-0628?
CVE-2003-0628 is a path disclosure vulnerability in the PeopleSoft Gateway Administration servlet.
5
What can attackers gain from exploiting CVE-2003-0628?
Exploiting CVE-2003-0628 allows attackers to obtain the full pathnames for server-side include (SSI) files.