SQL Injection Vulnerability in Oracle PeopleSoft Cash Management
CVE-2025-21537

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 January 2025

Summary

A SQL Injection vulnerability exists in the Oracle PeopleSoft Enterprise FIN Cash Management product affecting version 9.2. This flaw can be exploited by low-privileged attackers with network access via HTTP, allowing unauthorized manipulation of data. Successful exploitation could lead to unauthorized updates, insertions, deletions, and reading of sensitive data, compromising both confidentiality and integrity within the application. Organizations using this version are advised to apply security patches promptly to safeguard against potential breaches.

Affected Version(s)

PeopleSoft Enterprise FIN Cash Management 9.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.