peoplesoft CVE 脆弱性と CVE 一覧(9)

製品(CPE): — CVE 件数: 9

peoplesoft 脆弱性概要

This page aggregates publicly disclosed CVE and security risk information related to peoplesoft, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

脆弱性分布の推移(直近24か月)

表示中 19 / 9 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2006-0584 The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output strings. [email protected] 2.1 0.07% 2006-02-08 2026-04-16
CVE-2004-2435 Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitrary web script or HTML via unspecified (1) debugging or (2) utility scripts. [email protected] 4.3 0.55% 2004-12-31 2026-04-16
CVE-2003-0627 psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to cause a denial of service (application crash), possibly via the headername and footername arguments. [email protected] 5.0 0.91% 2003-12-31 2026-04-16
CVE-2003-0950 PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name of the directory used to store the file, and directly requesting that file. [email protected] 7.5 0.98% 2003-12-15 2026-04-16
CVE-2003-0629 Cross-site scripting (XSS) vulnerability in PeopleSoft IScript environment for PeopleTools 8.43 and earlier allows remote attackers to insert arbitrary web script via a certain HTTP request to IScript. [email protected] 4.3 0.30% 2003-12-15 2026-04-16
CVE-2003-0628 PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI) files via an HTTP request with an invalid value. [email protected] 5.0 0.50% 2003-12-15 2026-04-16
CVE-2003-0626 psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to read arbitrary files via the (1) headername or (2) footername arguments. [email protected] 5.0 0.76% 2003-11-13 2026-04-16
CVE-2003-0104 Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet. [email protected] 5.0 1.29% 2003-03-18 2026-04-16
CVE-2002-1252 The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the SimpleFileHandler handler. [email protected] 5.0 0.61% 2003-02-07 2026-04-16
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence