NEWS By Patrick Gray A serious vulnerability, which may allow attackers to obtain confidential information, has been found in PeopleSoft's Application Messaging Gateway servlet. Internet Security Systems (ISS), a network security company based in theUS, discovered the security glitch, present in default installations, and released an advisory. "The Application Messaging Gateway is configured to run by default on the PeopleSoft Web server," the advisory said. The vulnerability effects all 8.1x versions of PeopleTools, with the exception of 8.19. 8.4x versions are not affected. PeopleSoft users can upgrade to version 8.19, but they might have to wait a while. "PeopleSoft has addressed all of the issues described in this advisory in PeopleTools 8.19, available on PeopleSoft's Customer Connection site in early February," ISS said. In the meantime, until the update becomes available, ISS have recommended a series of workarounds. "ISS X-Force recommends that all PeopleSoft administrators block or restrict access to the servlets in question. X-Force also recommends that administrators take advantage of the security mechanisms that BEA WebLogic Servers provide," they said. ISS has been subjected to criticism in the past for hastily disclosing security vulnerabilities to the security community without allowing vendors or software companies an adequate timeframe in which to engineer security fixes. In June last year they issued a public advisory after discovering a critical security flaw in the Apache web server before notifying the Apache Software Foundation, the group responsible for maintaining the software. As a result it was some time before the appropriate security updates were made available. Patrick Gray, ZDNet Australia writes for ZDNet Australia
Users warned of PeopleSoft vulnerability
Make sure you're not affected...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Latest Software stories
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Systems engineering: Best practice for development success
Systems engineering isn't just a technical activity in the product lifecycle—it determines the commercial viability of...
-
The virtual presenter's handbook
Web seminars -- or webinars -- are online seminars or presentations used to engage remote audiences with any content...
-
Use product development for competitive advantage
Remember when MP3 players just played music? Today, consumers want players that can host music, stream video, support...
Popular Software stories
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Project Manager
Black Rock Studio [A division of Disney Interactive Media Group] is currently recruiting for a Project Manager to...
-
Senior Marketing Executive - Poole - £30,000
I am representing a market leading company based in the Bournemouth / Poole area that are urgently looking for...
-
SAP Senior PC Product Costing Consultant - FICO (FI/CO) - End User - Up to £85,000
SAP Senior PC Product Costing Consultant - FICO (FI/CO) - End User - Up to £85,000SAP Senior PC Product...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




