Search: "peoplesoft"

650 CVEs found

CVE-2002-1252
5.0 MEDIUM

The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fiel...

Published: 2003-02-07
Products: 5
Vendors:
peoplesoft
CVE-2003-0626
5.0 MEDIUM

psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to read arbitrary files via the (1) headername or (2) footername arguments.

Published: 2003-11-13
Products: 16
Vendors:
peoplesoft
CVE-2003-0841
5.0 MEDIUM

The grid option in PeopleSoft 8.42 stores temporary .xls files in guessable directories under the web document root, which allows remote attackers to steal search results by directly accessing the fil...

Published: 2003-11-17
Products: 1
Vendors:
oracle
CVE-2003-0628
5.0 MEDIUM

PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI) files via an HTTP ...

Published: 2003-12-15
Products: 16
Vendors:
peoplesoft
CVE-2003-0629
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in PeopleSoft IScript environment for PeopleTools 8.43 and earlier allows remote attackers to insert arbitrary web script via a certain HTTP request to IScript...

Published: 2003-12-15
Products: 16
Vendors:
peoplesoft

PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name of t...

Published: 2003-12-15
Products: 16
Vendors:
peoplesoft
CVE-2003-0627
5.0 MEDIUM

psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to cause a denial of service (application crash), possibly via the headername and footername arguments.

Published: 2003-12-31
Products: 4
Vendors:
peoplesoft
CVE-2004-2435
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitrary web script or HTM...

Published: 2004-12-31
Products: 1
Vendors:
peoplesoft
CVE-2005-3461
10.0 HIGH

Unspecified vulnerability in PeopleTools in Oracle PeopleSoft Enterprise 8.42 up to 8.45.17 has unknown impact and attack vectors, as identified by Oracle Vuln# PSE01.

Published: 2005-11-02
Products: 2
Vendors:
oracle
CVE-2005-3462
10.0 HIGH

Unspecified vulnerability in PeopleTools in Oracle PeopleSoft Enterprise 8.44 up to 8.46.02 has unknown impact and attack vectors, as identified by Oracle Vuln# PSE02.

Published: 2005-11-02
Products: 2
Vendors:
oracle
CVE-2005-3463
10.0 HIGH

Unspecified vulnerability in PeopleTools in Oracle PeopleSoft Enterprise 8.44 up to 8.46.03 has unknown impact and attack vectors, as identified by Oracle Vuln# PSE03.

Published: 2005-11-02
Products: 2
Vendors:
oracle
CVE-2005-3464
10.0 HIGH

Unspecified vulnerability in PeopleTools in Oracle PeopleSoft Enterprise 8.44 up to 8.46 has unknown impact and attack vectors, as identified by Oracle Vuln# PSE04.

Published: 2005-11-02
Products: 3
Vendors:
oracle
CVE-2006-0280
10.0 HIGH

Unspecified vulnerability in Oracle PeopleSoft Enterprise Portal 8.4 Bundle 15, 8.8 Bundle 10, and 8.9 Bundle 2 has unspecified impact and attack vectors, as identified by Oracle Vuln# PSE01.

Published: 2006-01-18
Products: 3
Vendors:
oracle

The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that...

Published: 2006-02-08
Products: 7
Vendors:
peoplesoft
CVE-2006-1886
10.0 HIGH

Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise 8.46.12 and 8.47.04 has unknown impact and attack vectors, aka Vuln# PSE01.

Published: 2006-04-20
Products: 2
Vendors:
oracle
CVE-2006-3722
10.0 HIGH

Unspecified vulnerability in PeopleSoft Enterprise Portal for Oracle PeopleSoft Enterprise Portal 8.4 Bundle #16, 8.8 Bundle #10, and 8.9 Bundle #3 has unknown impact and attack vectors, aka Oracle Vu...

Published: 2006-07-21
Products: 3
Vendors:
oracle
CVE-2006-3723
10.0 HIGH

Unspecified vulnerability in PeopleSoft Enterprise Portal for Oracle PeopleSoft Enterprise Portal 8.8 with Enforcer Portal Pack Bundle #10 and 8.9 Bundle #3 has unknown impact and attack vectors, aka ...

Published: 2006-07-21
Products: 2
Vendors:
oracle
CVE-2006-5375
10.0 HIGH

Multiple unspecified vulnerabilities in PeopleTools component in Oracle PeopleSoft Enterprise 8.46 GA, 8.47 GA, 8.48 GA, 8.46.15, 8.47.09, and 8.48.03 have unknown impact and remote attack vectors, ak...

Published: 2006-10-18
Products: 6
Vendors:
oracle

Multiple unspecified vulnerabilities in PeopleTools component in Oracle PeopleSoft Enterprise 8.22 GA, 8.46 GA, 8.47 GA, 8.48 GA, 8.22.11, 8.46.15, 8.47.09, and 8.48.03 have unknown impact and remote ...

Published: 2006-10-18
Products: 7
Vendors:
oracle

Unspecified vulnerability in PeopleSoft component in Oracle PeopleSoft Enterprise 8.80 GA, 8.90 GA, 8.8 Bundle 11, and 8.9 Bundle 4 has unknown impact and remote authenticated attack vectors, aka Vuln...

Published: 2006-10-18
Products: 4
Vendors:
oracle