PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name of the directory used to store the file, and directly requesting that file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Peopletools | Peoplesoft | 8.4 (including) | 8.4 (including) |
Peopletools | Peoplesoft | 8.10 (including) | 8.10 (including) |
Peopletools | Peoplesoft | 8.11 (including) | 8.11 (including) |
Peopletools | Peoplesoft | 8.12 (including) | 8.12 (including) |
Peopletools | Peoplesoft | 8.13 (including) | 8.13 (including) |
Peopletools | Peoplesoft | 8.14 (including) | 8.14 (including) |
Peopletools | Peoplesoft | 8.15 (including) | 8.15 (including) |
Peopletools | Peoplesoft | 8.16 (including) | 8.16 (including) |
Peopletools | Peoplesoft | 8.17 (including) | 8.17 (including) |
Peopletools | Peoplesoft | 8.18 (including) | 8.18 (including) |
Peopletools | Peoplesoft | 8.19 (including) | 8.19 (including) |
Peopletools | Peoplesoft | 8.20 (including) | 8.20 (including) |
Peopletools | Peoplesoft | 8.40 (including) | 8.40 (including) |
Peopletools | Peoplesoft | 8.41 (including) | 8.41 (including) |
Peopletools | Peoplesoft | 8.42 (including) | 8.42 (including) |
Peopletools | Peoplesoft | 8.43 (including) | 8.43 (including) |