Arbitrary File Read Vulnerability in PeopleSoft Application Messaging Gateway

Arbitrary File Read Vulnerability in PeopleSoft Application Messaging Gateway

CVE-2002-1252 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the SimpleFileHandler handler.

Learn more about our External Network Penetration Testing.