Low Privilege Vulnerability in Oracle PeopleSoft Enterprise CC Application
CVE-2025-21562
4.3MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 21 January 2025
Summary
A vulnerability exists in Oracle People's PeopleSoft Enterprise CC Common Application Objects, specifically in the Run Control Management component. This flaw allows low-privileged attackers with network access via HTTP to exploit the system. Successful exploitation can lead to unauthorized read access to a portion of the accessible data within the PeopleSoft system, which can have implications for data confidentiality. Consequently, organizations using this version should take measures to mitigate potential breaches and secure their applications.
Affected Version(s)
PeopleSoft Enterprise CC Common Application Objects 9.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved