PeopleSoft PeopleTools SchedulerTransfer Remote Command Execution Vulnerability
BID:7053
Info
PeopleSoft PeopleTools SchedulerTransfer Remote Command Execution Vulnerability
| Bugtraq ID: | 7053 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0104 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2003 12:00AM |
| Updated: | Jul 11 2009 09:06PM |
| Credit: | Discovery of this issue is credited to Neel Mehta of ISS X-Force. |
| Vulnerable: |
PeopleSoft PeopleTools 8.41 PeopleSoft PeopleTools 8.40 PeopleSoft PeopleTools 8.18 PeopleSoft PeopleTools 8.17 PeopleSoft PeopleTools 8.16 PeopleSoft PeopleTools 8.15 PeopleSoft PeopleTools 8.14 PeopleSoft PeopleTools 8.13 PeopleSoft PeopleTools 8.12 PeopleSoft PeopleTools 8.11 PeopleSoft PeopleTools 8.10 |
| Not Vulnerable: |
PeopleSoft PeopleTools 8.42 PeopleSoft PeopleTools 8.19 |
Discussion
PeopleSoft PeopleTools SchedulerTransfer Remote Command Execution Vulnerability
A remote command execution vulnerability exists in the PeopleSoft PeopleTools "SchedulerTransfer" servlet. This issue occurs because the servlet does not sufficiently validate externally supplied data. Exploitation may allow malicious files to be written to the system hosting the software and executed with the privileges of the web server.
A remote command execution vulnerability exists in the PeopleSoft PeopleTools "SchedulerTransfer" servlet. This issue occurs because the servlet does not sufficiently validate externally supplied data. Exploitation may allow malicious files to be written to the system hosting the software and executed with the privileges of the web server.
Exploit / POC
PeopleSoft PeopleTools SchedulerTransfer Remote Command Execution Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
PeopleSoft PeopleTools SchedulerTransfer Remote Command Execution Vulnerability
Solution:
PeopleSoft has addressed this issue in PeopleTools 8.19 and 8.42. Patches have also been released for PeopleTools 8.18.06 and 8.41.05. Users should contact the vendor for further details on obtaining fixes.
Solution:
PeopleSoft has addressed this issue in PeopleTools 8.19 and 8.42. Patches have also been released for PeopleTools 8.18.06 and 8.41.05. Users should contact the vendor for further details on obtaining fixes.
References
PeopleSoft PeopleTools SchedulerTransfer Remote Command Execution Vulnerability
References:
References:
- PeopleSoft PeopleTools Remote Command Execution Vulnerability (ISS X-Force)
- PeopleSoft Homepage (PeopleSoft)