CVE-2025-50062
8.1Oracle · PeopleSoft Enterprise HCM Global Payroll Core
A vulnerability in Oracle PeopleSoft Enterprise HCM Global Payroll Core allows low privileged attackers to modify or access sensitive payroll data via network-based HTTP requests.
Executive summary
A critical vulnerability in Oracle PeopleSoft Enterprise HCM Global Payroll Core enables low privileged attackers to compromise, manipulate, or exfiltrate sensitive payroll data.
Vulnerability
This flaw allows a low privileged attacker with network access to the application via HTTP to gain unauthorized read, write, or deletion access to critical payroll data. The vulnerability is easily exploitable without user interaction.
Business impact
The potential for unauthorized modification or theft of payroll data poses a significant risk to organizational integrity and regulatory compliance. With a CVSS score of 8.1, this vulnerability reflects a high severity impact on confidentiality and integrity, potentially leading to unauthorized salary adjustments, financial fraud, or the exposure of sensitive employee personal information.
Remediation
Immediate Action: Apply the vendor-provided security updates found in the Oracle July 2025 Critical Patch Update as soon as they become available.
Proactive Monitoring: Review application access logs for unusual patterns of HTTP requests originating from low privileged accounts and monitor database audit logs for unauthorized data modifications.
Compensating Controls: Implement strict network segmentation and restrict access to the PeopleSoft management interface to trusted internal segments only, utilizing a Web Application Firewall to filter suspicious HTTP traffic.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a clear risk to the confidentiality and integrity of global payroll operations. Given the high CVSS score and the potential for direct financial impact, administrators should prioritize applying the relevant security patches from the Oracle July 2025 CPU. Until patching is complete, ensure that access controls are rigorously enforced to minimize the potential for exploitation by malicious or compromised low privileged accounts.
More Oracle CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Analyst report written
Sources
- Oracle Advisory Vendor advisory