CVE-2002-1252
The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the…
Does this matter?
Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.
Description
The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the SimpleFileHandler handler.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Affected
- peoplesoft/peopletools
- Source
- cve@mitre.org
References
- http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21811Vendor Advisory
- http://www.iss.net/security_center/static/10520.phpPatch, Vendor Advisory
- http://www.securityfocus.com/bid/6647
- http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21811Vendor Advisory
- http://www.iss.net/security_center/static/10520.phpPatch, Vendor Advisory
- http://www.securityfocus.com/bid/6647
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.