[NT] PeopleSoft Gateway Administration Servlet Path Disclosure
From: SecuriTeam (support_at_securiteam.com)
Date: 11/16/03
- Previous message: SecuriTeam: "[UNIX] HP-UX libc NLSPATH Environment Variable Privilege Elevation Vulnerability"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 16 Nov 2003 17:53:54 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
PeopleSoft Gateway Administration Servlet Path Disclosure
------------------------------------------------------------------------
SUMMARY
The PeopleSoft Gateway Administration servlet provides a web-based
interface to configure handlers. In the event of an invalid value being
entered, the actual path of the server side configuration files is
disclosed in the error response.
DETAILS
Vulnerable systems:
* PeopleTools version 8.20, 8.43 and prior
The gateway.administration servlet is used within the PeopleSoft
environment to configure handlers. This application accepts a number of
values via an HTML form. If an invalid value is entered, then the servlet
responds with an error page that contains the actual path of the server
side configuration files.
This path can then be used in conjunction with other potential
vulnerabilities to attack specific OS and application configuration files.
Recommendations:
PeopleSoft have released details of this and other issues under security
rollup vulnerability ID 20031112, which is available to registered users
from the PeopleSoft
<http://www.peoplesoft.com/corp/en/patch_fix/search.jsp> support site.
PeopleSoft recommends that customers address the vulnerability by applying
the following fixes available on PeopleSoft Customer Connection.
Release Patch
8.18 8.18.15
8.19 8.19.12
8.20 8.20.03
8.42 8.42.14
8.43 8.43.11
For those who can not implement the patches promptly, as a mitigating
strategy a firewall or other HTTP filtering device can be used to block
queries containing sensitive strings, or as a last resort the
administration functionality of the PeopleSoft Gateway can be disabled by
restricting access to the servlet itself.
ADDITIONAL INFORMATION
The information has been provided by <mailto:martin.oneal@corsaire.com>
Martin O'Neal.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[UNIX] HP-UX libc NLSPATH Environment Variable Privilege Elevation Vulnerability"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [NEWS] PeopleSoft Control-J Information Disclosure
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... in, the name of the Database
logged into, the Database platform, and the ... CTLR-J and HTML object PT_INFOPAGE
will be displayed: ... June 03 PeopleSoft contacted ... (Securiteam) - [NT] PeopleSoft PeopleBooks Search CGI Multiple Argument Issues
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... - Cause a Denial of Services
on the web server host. ... PeopleSoft have released details of this and other issues
under security ... (Securiteam) - [NEWS] PeopleSoft Grid Option Vulnerability
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Attached to this solution (download
from PeopleSoft Solution ID: ... The script is for Microsoft SQL Server,
if you are on a different Database ... (Securiteam) - [NT] PeopleSoft IScript XSS Issue
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... PeopleSoft have
released details of this and other issues under security ... PeopleSoft recommends that customers
address the vulnerability by applying ... (Securiteam) - [UNIX] Trend Micro VirusWall Buffer Overflow in VSAPI Library
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... buffer overflow vulnerability
in VSAPI library allows arbitrary code ... is called "vscan" which is set suid root by
default. ... permissions and thus granted all local users the privilege to execute the
... (Securiteam)