CVE-2008-2616
published 2008-07-15CVE-2008-2616: Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown…
PriorityP426medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.57%
72.6th percentile
Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2617, CVE-2008-2618, CVE-2008-2620, CVE-2008-2621, and CVE-2008-2622.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | httpd | — | — |
| oracle | jd_edwards_enterpriseone | — | — |
| oracle | jd_edwards_enterpriseone | — | — |
| oracle | peoplesoft_enterprise | — | — |
| oracle | peoplesoft_enterprise | — | — |
| oracle | peoplesoft_peopletools | — | — |
| oracle | peoplesoft_peopletools | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_apache4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vg8x-r8gm-9mcp: Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8
ghsa_unreviewed·2022-05-01·CVSS 6.5
CVE-2008-2615 [MEDIUM] GHSA-vg8x-r8gm-9mcp: Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8
Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2616, CVE-2008-2617, CVE-2008-2618, CVE-2008-2620, CVE-2008-2621, and CVE-2008-2622.
GHSA
GHSA-g9wm-m86j-f72h: Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8
ghsa_unreviewed·2022-05-01·CVSS 6.5
CVE-2008-2622 [MEDIUM] GHSA-g9wm-m86j-f72h: Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8
Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2616, CVE-2008-2617, CVE-2008-2618, CVE-2008-2620, and CVE-2008-2621.
GHSA
GHSA-pj98-w72v-7m4m: Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8
ghsa_unreviewed·2022-05-01·CVSS 6.5
CVE-2008-2616 [MEDIUM] GHSA-pj98-w72v-7m4m: Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8
Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2617, CVE-2008-2618, CVE-2008-2620, CVE-2008-2621, and CVE-2008-2622.
GHSA
GHSA-356f-694x-6f4f: Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8
ghsa_unreviewed·2022-05-01·CVSS 6.5
CVE-2008-2621 [MEDIUM] GHSA-356f-694x-6f4f: Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8
Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2616, CVE-2008-2617, CVE-2008-2618, CVE-2008-2620, and CVE-2008-2622.
GHSA
GHSA-r68f-vv58-jpgh: Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8
ghsa_unreviewed·2022-05-01·CVSS 6.5
CVE-2008-2617 [MEDIUM] GHSA-r68f-vv58-jpgh: Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8
Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2616, CVE-2008-2618, CVE-2008-2620, CVE-2008-2621, and CVE-2008-2622.
GHSA
GHSA-63xq-wq3m-pq2p: Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8
ghsa_unreviewed·2022-05-01·CVSS 6.5
CVE-2008-2618 [MEDIUM] GHSA-63xq-wq3m-pq2p: Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8
Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2616, CVE-2008-2617, CVE-2008-2620, CVE-2008-2621, and CVE-2008-2622.
GHSA
GHSA-g8h5-wv99-85v5: Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8
ghsa_unreviewed·2022-05-01·CVSS 6.5
CVE-2008-2620 [MEDIUM] GHSA-g8h5-wv99-85v5: Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8
Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2616, CVE-2008-2617, CVE-2008-2618, CVE-2008-2621, and CVE-2008-2622.
Red Hat
httpd: XSS via UTF-7 encoded urls on the 403 Forbidden error page
vendor_redhat·2008-05-08·CVSS 4.3
CVE-2008-2168 [MEDIUM] CWE-79 httpd: XSS via UTF-7 encoded urls on the 403 Forbidden error page
httpd: XSS via UTF-7 encoded urls on the 403 Forbidden error page
Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
Statement: This is actually a flaw in browsers that do not derive the response character set as required by RFC 2616. This does not affect the default configuration of Apache httpd in Red Hat products and will only affect customers who have removed the "AddDefaultCharset" directive.
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-2168
Apache
Apache httpd: CVE-2008-0005
vendor_apache·CVSS 4.3
CVE-2008-0005 [LOW] Apache httpd: CVE-2008-0005
Apache httpd: CVE-2008-0005
A workaround was added in the mod_proxy_ftp module. On sites where mod_proxy_ftp is enabled and a forward proxy is configured, a cross-site scripting attack is possible against Web browsers which do not correctly derive the response character set following the rules in RFC 2616. Reported to security team 2007-12-15 Issue public 2008-01-08 Update 2.0.63 released 2008-01-19 Update 2.2.8 released 2008-01-19 Affects 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, 2.2.0, 2.0.61, 2.0.59, 2.0.58, 2.0.55, 2.0.54, 2.0.53, 2.0.52, 2.0.51, 2.0.50, 2.0.49, 2.0.48, 2.0.47, 2.0.46, 2.0.45, 2.0.44, 2.0.43, 2.0.42, 2.0.40, 2.0.39, 2.0.37, 2.0.36, 2.0.35
Severity: low
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00727143http://secunia.com/advisories/31087http://secunia.com/advisories/31113http://www.oracle.com/technetwork/topics/security/cpujul2008-090335.htmlhttp://www.securitytracker.com/id?1020497http://www.vupen.com/english/advisories/2008/2109/referenceshttp://www.vupen.com/english/advisories/2008/2115https://exchange.xforce.ibmcloud.com/vulnerabilities/43818http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00727143http://secunia.com/advisories/31087http://secunia.com/advisories/31113http://www.oracle.com/technetwork/topics/security/cpujul2008-090335.htmlhttp://www.securitytracker.com/id?1020497http://www.vupen.com/english/advisories/2008/2109/referenceshttp://www.vupen.com/english/advisories/2008/2115https://exchange.xforce.ibmcloud.com/vulnerabilities/43818
2008-07-15
Published