First published: Thu Oct 09 2003(Updated: )
The grid option in PeopleSoft 8.42 stores temporary .xls files in guessable directories under the web document root, which allows remote attackers to steal search results by directly accessing the files via a URL request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Peopletools | =8.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0841 is considered a high severity vulnerability due to the potential for unauthorized access to sensitive data.
To fix CVE-2003-0841, you should modify the configuration to prevent temporary .xls files from being stored in guessable directories.
CVE-2003-0841 affects Oracle PeopleTools version 8.42.
CVE-2003-0841 is a directory traversal vulnerability that allows remote file access.
Yes, CVE-2003-0841 can lead to data theft as attackers can access search result files stored on the server.