CVE-2025-21530: Medium severity oracle peopletools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21530?
CVE-2025-21530 is considered to be an easily exploitable vulnerability that affects Oracle PeopleSoft Enterprise.
How do I fix CVE-2025-21530?
To remediate CVE-2025-21530, upgrade affected versions of Oracle PeopleSoft Enterprise PeopleTools from 8.60 or 8.61 to the latest patched version.
Who is affected by CVE-2025-21530?
CVE-2025-21530 affects users of Oracle PeopleSoft Enterprise PeopleTools versions 8.60 and 8.61.
What can an attacker do with CVE-2025-21530?
A low privileged attacker with network access via HTTP can exploit CVE-2025-21530 to compromise PeopleSoft Enterprise.
What products does CVE-2025-21530 impact?
CVE-2025-21530 specifically impacts the PeopleSoft Enterprise PeopleTools component of Oracle's software.