what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

peoplesoft842.txt

peoplesoft842.txt
Posted Oct 7, 2003
Authored by Barrett McGuire, Larry Wargo, Matt Fotter

PeopleSoft People Tools version 8.42 allows for a remote user to save Excel formatted files on the webserver which inadvertently allows them to be accessed by a remote unauthenticated attacker.

tags | advisory, remote
SHA-256 | ad7cb2fb7e14daa25721c74a672125bdb71c19fd228012b0c80520a1bceeae2d

peoplesoft842.txt

Change Mirror Download
Vendor:            PeopleSoft
PS Solution ID: 200749183
Product: People Tools
Version: 8.42
Platform: Solaris 8, BEA WebLogic, Others?
Remote/Local: Remote, Unauthenticated
Title: File Availability
Impact: Data accessible by Everyone.

Description:
PeopleTools 8.42 has a "grid" option, which allows a user to save a search to an .xls file. The .xls file is displayed in the local browser, allowing a user to do a "Save As" to save to local hard drive. The output file is also saved as a temporarily-resident copy on the web server without restrictions.

Any user, without authenticating, can browse to the direct URL location and access the file. The file appears to stay in this location for approximately 5 minutes before you get the '404 File not found' error.

The application makes the file available by storing it on the webserver for a period of time that is hard coded into the java servlet. The file is stored in a directory with a random name, however, the random directory name could be determined using automated tools and since the file itself is not secured, it is potentially accessible by unauthorized users.


Vendor Solution:
Attached to this solution (download from PeopleSoft--see above Solution ID) is a script to make the download to Excel buttons invisible. The script is for Microsoft SQL Server, if you are on a different Database platform, you will have to make the necessary changes to the script.

NOTE: The script is NOT designed to make it easy for you to return to your prior state after the script has been applied. Additionally, this script is provided as a convenience, and is not supported by GSC.

PLEASE REMEMBER, this is considered to be a customization beyond the scope of the Global Support Center. We are delivering a script that works in Microsoft SQL Server with no plans to create different scripts for the different Database platforms.

Vendor Trail:
3 June 03 PeopleSoft contacted
3 June 03 PeopleSoft confirms
24 June 03 PeopleSoft teleconference
19 July 03 PeopleSoft posts to Customer Connection


Contributers:
Barrett McGuire
Larry Wargo
Matt Fotter
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    17 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close