CVE-2013-2408
published 2013-04-17CVE-2013-2408: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.98%
58.3th percentile
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect integrity via vectors related to PIA Core Technology and use of Internet Explorer 6.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | peoplesoft_products | — | — |
| oracle | peoplesoft_products | — | — |
| oracle | peoplesoft_products | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wj76-4fqw-24hh: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8
ghsa_unreviewed·2022-05-17
CVE-2013-2408 [MEDIUM] GHSA-wj76-4fqw-24hh: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect integrity via vectors related to PIA Core Technology and use of Internet Explorer 6.
Red Hat
php: hostname check bypassing vulnerability in SSL client
vendor_redhat·2013-08-13·CVSS 5.9
CVE-2013-4248 [MEDIUM] php: hostname check bypassing vulnerability in SSL client
php: hostname check bypassing vulnerability in SSL client
The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Statement: This issue does not affect the version of php as shipped with Red Hat Enterprise Linux 5 or the version of php54 as shipped with Red Hat Software Collections 1.
Package: php (Red Hat Enterprise Linux 5) - Not affected
Package: php (Red Hat Enterprise Linux 7) - Not affected
Package: php54-php (Red Hat Software C
Red Hat
python: hostname check bypassing vulnerability in SSL module
vendor_redhat·2013-08-12·CVSS 5.9
CVE-2013-4238 [MEDIUM] python: hostname check bypassing vulnerability in SSL module
python: hostname check bypassing vulnerability in SSL module
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Statement: This issue does not affect the version of python as shipped with Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this issue as having moderate security impact, a future update may address this flaw.
Package: python (Red Hat Enterprise Linux 5) - Not affected
Package: python (Red Hat Enterprise Linux 7) - Not affected
P
Red Hat
ruby: hostname check bypassing vulnerability in SSL client
vendor_redhat·2013-06-27·CVSS 5.9
CVE-2013-4073 [MEDIUM] ruby: hostname check bypassing vulnerability in SSL client
ruby: hostname check bypassing vulnerability in SSL client
The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in Ruby 1.8 before 1.8.7-p374, 1.9 before 1.9.3-p448, and 2.0 before 2.0.0-p247 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Package: ruby (Red Hat Enterprise Linux 7) - Not affected
Package: jruby (Red Hat JBoss SOA Platform 4) - Will not fix
Package: jruby (Red Hat JBoss SOA Platform 5) - Will not fix
Package: ruby193-ruby (Red Hat Software Collections) - Affected
Package: ruby193-ruby (Red Hat Su
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-04-17
Published