CVE Vulnerabilities

CVE-2003-0950

Published: Dec 15, 2003 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name of the directory used to store the file, and directly requesting that file.

Affected Software

Name Vendor Start Version End Version
Peopletools Peoplesoft 8.4 (including) 8.4 (including)
Peopletools Peoplesoft 8.10 (including) 8.10 (including)
Peopletools Peoplesoft 8.11 (including) 8.11 (including)
Peopletools Peoplesoft 8.12 (including) 8.12 (including)
Peopletools Peoplesoft 8.13 (including) 8.13 (including)
Peopletools Peoplesoft 8.14 (including) 8.14 (including)
Peopletools Peoplesoft 8.15 (including) 8.15 (including)
Peopletools Peoplesoft 8.16 (including) 8.16 (including)
Peopletools Peoplesoft 8.17 (including) 8.17 (including)
Peopletools Peoplesoft 8.18 (including) 8.18 (including)
Peopletools Peoplesoft 8.19 (including) 8.19 (including)
Peopletools Peoplesoft 8.20 (including) 8.20 (including)
Peopletools Peoplesoft 8.40 (including) 8.40 (including)
Peopletools Peoplesoft 8.41 (including) 8.41 (including)
Peopletools Peoplesoft 8.42 (including) 8.42 (including)
Peopletools Peoplesoft 8.43 (including) 8.43 (including)

References