Vulnerability in Oracle PeopleSoft Enterprise FIN eSettlements Product
CVE-2025-21539

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 January 2025

Summary

A security issue exists in Oracle's PeopleSoft Enterprise FIN eSettlements product. This vulnerability is easily exploitable, permitting a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation can lead to unauthorized updates, insertions, and deletions of data, along with unauthorized reading of sensitive information within PeopleSoft Enterprise FIN eSettlements. Organizations using the affected version, 9.2, should take prompt action to secure their systems against this threat.

Affected Version(s)

PeopleSoft Enterprise FIN eSettlements 9.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.