Peoplesoft
7 CVEs tracked since 2003. Since Nov 2003, none of them reached CISA KEV.
Peoplesoft CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2003-11 | 3 | 0 |
| 2003-12 | null or fewer | |
| 2004-01 | null or fewer | |
| 2004-02 | null or fewer | |
| 2004-03 | null or fewer | |
| 2004-04 | null or fewer | |
| 2004-05 | null or fewer | |
| 2004-06 | null or fewer | |
| 2004-07 | null or fewer | |
| 2004-08 | null or fewer | |
| 2004-09 | 2 | 0 |
| 2004-10 | null or fewer | |
| 2004-11 | null or fewer | |
| 2004-12 | null or fewer | |
| 2005-01 | null or fewer | |
| 2005-02 | null or fewer | |
| 2005-03 | null or fewer | |
| 2005-04 | 2 | 0 |
Products
The products that kept showing up in Peoplesoft's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 9 most recently published vulnerabilities affecting Peoplesoft.
- CVE-2006-0584The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack t...2.1
- CVE-2004-2435Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitrary web script or ...4.3
- CVE-2003-0627psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to cause a denial of service (application crash), possibly via the headername and footername arguments.5.0
- CVE-2003-0626psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to read arbitrary files via the (1) headername or (2) footername arguments.5.0
- CVE-2002-1252The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) f...5.0
- CVE-2003-0104Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.5.0
- CVE-2003-0950PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name o...7.5
- CVE-2003-0629Cross-site scripting (XSS) vulnerability in PeopleSoft IScript environment for PeopleTools 8.43 and earlier allows remote attackers to insert arbitrary web script via a certain HTTP request to IScr...4.3
- CVE-2003-0628PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI) files via an HT...5.0
The record
- Peak rank
- #6 in Nov 2003
- Busiest month shown
- Nov 2003, 3 CVEs
- Months with a KEV entry
- 0 since Nov 2003
- Monthly snapshots
- 3 since 2003