CVE Vulnerabilities

CVE-2003-0950

Published: Dec 15, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name of the directory used to store the file, and directly requesting that file.

Affected Software

NameVendorStart VersionEnd Version
PeopletoolsPeoplesoft8.4 (including)8.4 (including)
PeopletoolsPeoplesoft8.10 (including)8.10 (including)
PeopletoolsPeoplesoft8.11 (including)8.11 (including)
PeopletoolsPeoplesoft8.12 (including)8.12 (including)
PeopletoolsPeoplesoft8.13 (including)8.13 (including)
PeopletoolsPeoplesoft8.14 (including)8.14 (including)
PeopletoolsPeoplesoft8.15 (including)8.15 (including)
PeopletoolsPeoplesoft8.16 (including)8.16 (including)
PeopletoolsPeoplesoft8.17 (including)8.17 (including)
PeopletoolsPeoplesoft8.18 (including)8.18 (including)
PeopletoolsPeoplesoft8.19 (including)8.19 (including)
PeopletoolsPeoplesoft8.20 (including)8.20 (including)
PeopletoolsPeoplesoft8.40 (including)8.40 (including)
PeopletoolsPeoplesoft8.41 (including)8.41 (including)
PeopletoolsPeoplesoft8.42 (including)8.42 (including)
PeopletoolsPeoplesoft8.43 (including)8.43 (including)

References