← Back

Peopletools

peopletools

Vendor: Peoplesoft • 8 CVEs

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Peoplesoft
1Peopletools
Apr 16, 2026
Feb 8, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output str...Show more
The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output strings.Show less
1Peoplesoft
1Peopletools
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to cause a denial of service (application crash), possibly via the headername and footername arguments.
1Peoplesoft
1Peopletools
Apr 16, 2026
Dec 15, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name of the directory used to...Show more
PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name of the directory used to store the file, and directly requesting that file.Show less
1Peoplesoft
1Peopletools
Apr 16, 2026
Dec 15, 2003
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in PeopleSoft IScript environment for PeopleTools 8.43 and earlier allows remote attackers to insert arbitrary web script via a certain HTTP request to IScript.
1Peoplesoft
1Peopletools
Apr 16, 2026
Dec 15, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI) files via an HTTP request with an inva...Show more
PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI) files via an HTTP request with an invalid value.Show less
1Peoplesoft
1Peopletools
Apr 16, 2026
Nov 13, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to read arbitrary files via the (1) headername or (2) footername arguments.
1Peoplesoft
1Peopletools
Apr 16, 2026
Mar 18, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.
1Peoplesoft
1Peopletools
Apr 16, 2026
Feb 7, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST r...Show more
The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the SimpleFileHandler handler.Show less