Remote Denial of Service Vulnerability in Oracle PeopleSoft Enterprise PeopleTools
CVE-2025-21545
7.5HIGH
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 21 January 2025
What is CVE-2025-21545?
An exploitable vulnerability exists in the OpenSearch component of Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.60 and 8.61. This flaw enables unauthenticated attackers to gain network access via HTTP, potentially leading to a denial of service. Attackers can leverage this vulnerability to disrupt service, causing frequent crashes or system hangs without any authentication requirement.
Affected Version(s)
PeopleSoft Enterprise PeopleTools 8.60
PeopleSoft Enterprise PeopleTools 8.61