PeopleSoft PeopleTools contains a flaw that may lead to an unauthorized password exposure. It is possible to gain access to plain-text user ID's and passwords in PeopleTools log files on installations where xmllinks are used, which may lead to a loss of confidentiality.
Classification
Location:
Local Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Patch / RCS,
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
Solution
Upgrade to version 8.47.06 or higher for the 8.47 line, or 8.46.14 or higher for the 8.46 line, as it has been reported to fix this vulnerability. In addition, Oracle has released a patch for some older versions: Solution 662027 for PeopleTools 8.47.05, and Solution 662061 for PeopleTools 8.46.13
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.