[NT] PeopleSoft PeopleBooks Search CGI Multiple Argument Issues
From: SecuriTeam (support_at_securiteam.com)
Date: 11/16/03
- Previous message: SecuriTeam: "[NT] PeopleSoft IScript XSS Issue"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 16 Nov 2003 17:49:26 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
PeopleSoft PeopleBooks Search CGI Multiple Argument Issues
------------------------------------------------------------------------
SUMMARY
The PeopleSoft PeopleBooks component provides a CGI based search
application as part of the default installation. Several of the attributes
that are passed into the CGI application allow the specification of a
server-side path. By entering various path values into this argument it is
possible to:
- Access arbitrary files outside of the web servers document root.
- Cause a Denial of Services (DoS) on the web server host.
DETAILS
Vulnerable systems:
* PeopleTools version 8.20, 8.43 and prior
The Search CGI application (psdoccgi.exe) is used within the PeopleBooks
online documentation. This application accepts two arguments, headername
and footername, that allow the selection of header and footer content to
be returned as part of the search results HTML page.
These arguments appear to be checked for basic formatting issues. However,
it is still possible to access files outside of the web server root, such
as configuration files, that may contain passwords or other confidential
information.
Recommendations:
PeopleSoft have released details of this and other issues under security
rollup vulnerability ID 20031112, which is available to registered users
from the PeopleSoft
<http://www.peoplesoft.com/corp/en/patch_fix/search.jsp> support site.
PeopleSoft recommends that customers address the vulnerability by applying
the following fixes available on PeopleSoft Customer Connection.
Release Patch
8.18 8.18.15
8.19 8.19.12
8.20 8.20.03
8.42 8.42.14
8.43 8.43.11
For those who can not implement the patches promptly, as a mitigating
strategy a firewall or other HTTP filtering device can be used to block
queries containing sensitive strings, or as a last resort all access to
the PeopleSoft application can be disabled in entirety.
ADDITIONAL INFORMATION
The information has been provided by <mailto:martin.oneal@corsaire.com>
Martin O'Neal.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[NT] PeopleSoft IScript XSS Issue"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [NEWS] PeopleSoft Control-J Information Disclosure
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... in, the name of the Database
logged into, the Database platform, and the ... CTLR-J and HTML object PT_INFOPAGE
will be displayed: ... June 03 PeopleSoft contacted ... (Securiteam) - [NEWS] PeopleSoft Grid Option Vulnerability
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Attached to this solution (download
from PeopleSoft Solution ID: ... The script is for Microsoft SQL Server,
if you are on a different Database ... (Securiteam) - [NT] PeopleSoft Gateway Administration Servlet Path Disclosure
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... The gateway.administration servlet
is used within the PeopleSoft ... PeopleSoft recommends that customers address the vulnerability
by applying ... (Securiteam) - [UNIX] PHP / Apache DoS (Resource Consumption)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... PHP and Apache based
hosting is becoming very popular these days. ... of service attack against the web server
can be created using a very ... (Securiteam) - [NT] PeopleSoft IScript XSS Issue
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... PeopleSoft have
released details of this and other issues under security ... PeopleSoft recommends that customers
address the vulnerability by applying ... (Securiteam)