CVE-2025-21561: Medium severity oracle peoplesoft enterprise supply chain management services procurement vulnerability
Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM Purchasing accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise SCM Purchasing accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21561?
CVE-2025-21561 is considered to be easily exploitable and has a low privilege requirement for attackers.
Who is affected by CVE-2025-21561?
CVE-2025-21561 affects users of Oracle PeopleSoft Enterprise SCM Purchasing version 9.2.
How can I fix CVE-2025-21561?
To mitigate CVE-2025-21561, it is recommended to apply the latest security patches provided by Oracle for PeopleSoft Enterprise SCM Purchasing.
What type of access is required to exploit CVE-2025-21561?
An attacker needs network access via HTTP to exploit CVE-2025-21561.
What component of Oracle PeopleSoft is vulnerable in CVE-2025-21561?
CVE-2025-21561 affects the Purchasing component of the PeopleSoft Enterprise SCM product.