{"api_version":"1","generated_at":"2026-07-24T21:12:15+00:00","cve":"CVE-2002-1252","urls":{"html":"https://cve.report/CVE-2002-1252","api":"https://cve.report/api/cve/CVE-2002-1252.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-1252","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-1252"},"summary":{"title":"CVE-2002-1252","description":"The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the SimpleFileHandler handler.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-02-07 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21811","name":"http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21811","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/10520.php","name":"http://www.iss.net/security_center/static/10520.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"ISS X-Force Database: peoplesoft-xxe-read-files (10520): PeopleSoft Application Messaging Gateway XML External Entities (XXE) attack can be used to read files","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/6647","name":"http://www.securityfocus.com/bid/6647","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PeopleSoft XML External Entity Remote File Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-1252","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-1252","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"1252","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"peoplesoft","cpe5":"peopletools","cpe6":"8.14","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1252","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"peoplesoft","cpe5":"peopletools","cpe6":"8.15","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1252","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"peoplesoft","cpe5":"peopletools","cpe6":"8.16","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1252","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"peoplesoft","cpe5":"peopletools","cpe6":"8.17","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1252","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"peoplesoft","cpe5":"peopletools","cpe6":"8.18","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:19:28.224Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"peoplesoft-xxe-read-files(10520)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/10520.php"},{"name":"20030120 PeopleSoft XML External Entities Vulnerability","tags":["third-party-advisory","x_refsource_ISS","x_transferred"],"url":"http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21811"},{"name":"6647","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6647"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-01-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the SimpleFileHandler handler."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2008-02-07T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"peoplesoft-xxe-read-files(10520)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/10520.php"},{"name":"20030120 PeopleSoft XML External Entities Vulnerability","tags":["third-party-advisory","x_refsource_ISS"],"url":"http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21811"},{"name":"6647","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6647"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-1252","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the SimpleFileHandler handler."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"peoplesoft-xxe-read-files(10520)","refsource":"XF","url":"http://www.iss.net/security_center/static/10520.php"},{"name":"20030120 PeopleSoft XML External Entities Vulnerability","refsource":"ISS","url":"http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21811"},{"name":"6647","refsource":"BID","url":"http://www.securityfocus.com/bid/6647"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-1252","datePublished":"2004-09-01T04:00:00.000Z","dateReserved":"2002-11-01T00:00:00.000Z","dateUpdated":"2024-08-08T03:19:28.224Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-02-07 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:peoplesoft:peopletools:8.14:*:*:*:*:*:*:*","matchCriteriaId":"9ADCBDC1-C291-4978-95CC-2955AF9F0149"},{"vulnerable":true,"criteria":"cpe:2.3:a:peoplesoft:peopletools:8.15:*:*:*:*:*:*:*","matchCriteriaId":"623DDE5E-20CF-4002-A532-E1B0171FF0C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:peoplesoft:peopletools:8.16:*:*:*:*:*:*:*","matchCriteriaId":"55820FF1-2A48-4699-8C90-90CBC0C2D6A4"},{"vulnerable":true,"criteria":"cpe:2.3:a:peoplesoft:peopletools:8.17:*:*:*:*:*:*:*","matchCriteriaId":"EAD1CF68-901D-4366-81F1-20E561BEB405"},{"vulnerable":true,"criteria":"cpe:2.3:a:peoplesoft:peopletools:8.18:*:*:*:*:*:*:*","matchCriteriaId":"3B7B6AF6-2C2B-4186-911A-63D7CCE34E79"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"1252","Ordinal":"1","Title":"CVE-2002-1252","CVE":"CVE-2002-1252","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"1252","Ordinal":"1","NoteData":"The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the SimpleFileHandler handler.","Type":"Description","Title":"CVE-2002-1252"},{"CveYear":"2002","CveId":"1252","Ordinal":"2","NoteData":"2004-09-01","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"1252","Ordinal":"3","NoteData":"2008-02-06","Type":"Other","Title":"Modified"}]}}}