CVE-2002-1252
Last modified
CVE-2002-1252 is a vulnerability of currently unknown severity. The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the SimpleFileHandler handler.. EPSS estimates a 1.37% chance of exploitation in the next 30 days.
Description
The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the SimpleFileHandler handler.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Peoplesoft | Peopletools | 8.14 |
| Peoplesoft | Peopletools | 8.15 |
| Peoplesoft | Peopletools | 8.16 |
| Peoplesoft | Peopletools | 8.17 |
| Peoplesoft | Peopletools | 8.18 |
References
- http://www.iss.net/security_center/static/10520.phpPatch, Vendor Advisory
- http://www.iss.net/security_center/static/10520.phpPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-1252?
How severe is CVE-2002-1252?
How do I fix CVE-2002-1252?
Are you affected by CVE-2002-1252?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
