Skip to main content

Vendor/product archive

peoplesoft / peopletools CVEs

Beta · best-effort

8 CVEs tagged to peoplesoft / peopletools0 Critical, 1 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2006-0584

Published Feb 8, 2006

The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a d…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0627

Published Dec 31, 2003

psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to cause a denial of service (application crash), possibly via the headername and footername argume…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0628

Published Dec 15, 2003

PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SS…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0629

Published Dec 15, 2003

Cross-site scripting (XSS) vulnerability in PeopleSoft IScript environment for PeopleTools 8.43 and earlier allows remote attackers to insert arbitrary web script via a certain HT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0950

Published Dec 15, 2003

PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0626

Published Nov 13, 2003

psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to read arbitrary files via the (1) headername or (2) footername arguments.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0104

Published Mar 18, 2003

Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1252

Published Feb 7, 2003

The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML Externa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1