CNNVD-202510-2667 Information

CNNVD ID

CNNVD-202510-2667

CVE-2025-61758

  • CNNVD Published: 2025-10-21

Description (Chinese)

Oracle PeopleSoft是美国甲骨文(Oracle)公司的一套企业人力资本管理解决方案。该产品提供了人力资本管理、财务管理、供应商关系管理等功能。 Oracle PeopleSoft的PeopleSoft Enterprise FIN IT Asset Management 9.2版本存在安全漏洞,该漏洞源于低权限攻击者可通过HTTP网络访问进行攻击,可能导致未经授权访问关键数据或完全访问所有数据。

Description (English)

Oracle PeopleSoft is an enterprise human capital management solution for Oracle. The product provides human capital management, financial management and supplier relationship management functions. The PeopleSoft Enterprise FIN IT Assembly Management 9.2 version of Oracle PeopleSoft has a security loophole, which stems from the fact that low-authorized assailants can attack via the HTTP network, which may result in unauthorized access to key data or full access to all data.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

甲骨文

Published

2025-10-21

Last Modified

2026-02-24

References

https://www.oracle.com/security-alerts/cpuoct2025.html https://access.redhat.com/security/cve/cve-2025-61758

Patch

https://www.oracle.com/security-alerts/cpuoct2025.html

Share on: