Exploitable Vulnerability in PeopleSoft Enterprise PeopleTools by Oracle
CVE-2025-53048

5.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 October 2025

What is CVE-2025-53048?

A vulnerability exists in Oracle's PeopleSoft Enterprise PeopleTools, specifically within the Rich Text Editor component. This flaw allows attackers with low privileges to exploit the system via HTTP. The vulnerability requires a human interaction from a third party, highlighting its exploitability. While primarily affecting PeopleSoft Enterprise PeopleTools versions 8.60, 8.61, and 8.62, the implications of such attacks can extend to broader product functionalities, allowing unauthorized access to modify or interact with accessible data. The potential for significant data breaches calls for immediate investigation and remediation.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.60

PeopleSoft Enterprise PeopleTools 8.61

PeopleSoft Enterprise PeopleTools 8.62

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53048 : Exploitable Vulnerability in PeopleSoft Enterprise PeopleTools by Oracle