CVE-2002-1252
Summary
| CVE | CVE-2002-1252 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-02-07 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the SimpleFileHandler handler. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Peoplesoft | Peopletools | 8.14 | All | All | All |
| Application | Peoplesoft | Peopletools | 8.15 | All | All | All |
| Application | Peoplesoft | Peopletools | 8.16 | All | All | All |
| Application | Peoplesoft | Peopletools | 8.17 | All | All | All |
| Application | Peoplesoft | Peopletools | 8.18 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp | af854a3a-2127-422b-91ae-364da2661108 | bvlive01.iss.net | Vendor Advisory |
| ISS X-Force Database: peoplesoft-xxe-read-files (10520): PeopleSoft Application Messaging Gateway XML External Entities (XXE) attack can be used to read files | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Patch, Vendor Advisory |
| PeopleSoft XML External Entity Remote File Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.