CVE-2025-21539
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2025-21539 is a vulnerability affecting the Oracle PeopleSoft Enterprise FIN eSettlements product, specifically version 9.2. This issue enables a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation can grant an attacker unauthorized access to update, insert, or delete some PeopleSoft Enterprise FIN eSettlements data, along with unauthorized read access to a subset of the data. The base score of this vulnerability, according to the Common Vulnerability Scoring System version 3.1, is 5.4 for both confidentiality and integrity impacts. Attack vectors include network access, requiring low privileges and no user interaction.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.