CVE-2003-0841: Medium severity Oracle Peopletools vulnerability
Published Oct 9, 2003
·Updated
The grid option in PeopleSoft 8.42 stores temporary .xls files in guessable directories under the web document root, which allows remote attackers to steal search results by directly accessing the files via a URL request.
Affected Software
1 affected component
Oracle Peopletools=8.42
Event History
Oct 9, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Nov 17, 2003
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0841?
CVE-2003-0841 is considered a high severity vulnerability due to the potential for unauthorized access to sensitive data.
2
How do I fix CVE-2003-0841?
To fix CVE-2003-0841, you should modify the configuration to prevent temporary .xls files from being stored in guessable directories.
3
What systems are affected by CVE-2003-0841?
CVE-2003-0841 affects Oracle PeopleTools version 8.42.
4
What type of vulnerability is CVE-2003-0841?
CVE-2003-0841 is a directory traversal vulnerability that allows remote file access.
5
Can CVE-2003-0841 lead to data theft?
Yes, CVE-2003-0841 can lead to data theft as attackers can access search result files stored on the server.