PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name of the directory used to store the file, and directly requesting that file.
Link | Tags |
---|---|
http://xforce.iss.net/xforce/alerts/id/157 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/12805 | vdb entry |
http://www.securityfocus.com/bid/9041 | vdb entry vendor advisory |