Remote Code Execution Vulnerability in Oracle PeopleSoft Enterprise PeopleTools
CVE-2025-30748

6.1MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 July 2025

What is CVE-2025-30748?

An unauthenticated vulnerability exists in Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.60, 8.61, and 8.62. An attacker with network access via HTTP can exploit this issue, requiring human interaction from a third party to execute the attack. While primarily impacting PeopleSoft Enterprise PeopleTools, the potential for scope changes allows unauthorized updates, inserts, and deletions of accessible data, as well as unauthorized read access to sensitive information. This vulnerability underscores the necessity for robust security measures in systems utilizing PeopleSoft technology.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.60

PeopleSoft Enterprise PeopleTools 8.61

PeopleSoft Enterprise PeopleTools 8.62

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.