PT-2025-4259 · Oracle · Peoplesoft Enterprise Fin Cash Management

Published

2025-01-21

·

Updated

2025-06-20

·

CVE-2025-21537

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PeopleSoft Enterprise FIN Cash Management version 9.2
Description The issue is related to weaknesses in the authorization mechanism of the Cash Management component in PeopleSoft Enterprise FIN Cash Management. This can be exploited by a remote attacker using HTTP requests, potentially compromising the confidentiality and integrity of protected information. Successful attacks may result in unauthorized update, insert, or delete access to some accessible data, as well as unauthorized read access to a subset of accessible data.
Recommendations For version 9.2, consider restricting access to the Cash Management component until a patch is available. As a temporary workaround, limit the use of HTTP requests to the affected component to minimize the risk of exploitation. Avoid using the vulnerable Cash Management component for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-01293
CVE-2025-21537

Affected Products

Peoplesoft Enterprise Fin Cash Management