PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-60931 Infor CVE debrief

An Insecure Direct Object Reference (IDOR) vulnerability exists in Infor Global HR v11.24.10.01.33, allowing unauthorized attackers to view compensation information of other employees via crafted GET requests. This IDOR vulnerability can lead to potential unauthorized access to sensitive employee compensation information. Defenders should verify exposure, restrict access, and monitor for suspicious requests. The CVE record and NVD entry provide details on the IDOR vulnerability in Infor Global HR. However, specific versions and remediation details are limited. To address this vulnerability, defenders should prioritize verifying exposure of Infor Global HR v11.24.10.01.33 to this ID

Vendor
Infor
Product
Global HR
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-29
Original CVE updated
2026-10-05
Advisory published
2026-07-29
Advisory updated
2026-10-05

Who should care

Defenders responsible for Infor Global HR deployments should assess exposure to this IDOR vulnerability and take steps to restrict access to employee compensation views.

Why it matters

This IDOR vulnerability in Infor Global HR v11.24.10.01.33 allows unauthorized access to employee compensation information. Defenders should verify exposure, restrict access, and monitor for suspicious requests.

  • Potential unauthorized access to sensitive employee compensation information
  • Possible data exposure through crafted GET requests
  • Need for verification of Infor Global HR version exposure
  • Potential impact on employee data confidentiality

Technical summary

The Infor Global HR v11.24.10.01.33 contains an Insecure Direct Object Reference (IDOR) vulnerability in the Employee Compensation View function. This allows unauthorized attackers to view compensation information of other employees via crafted GET requests.

Defensive priority

Defenders should prioritize verifying exposure of Infor Global HR v11.24.10.01.33 to this IDOR vulnerability and restrict access to employee compensation views.

Recommended defensive actions

  • Verify Infor Global HR v11.24.10.01.33 exposure to this IDOR vulnerability
  • Restrict access to employee compensation views
  • Monitor for suspicious GET requests to employee compensation pages

Evidence notes

The CVE record and NVD entry provide details on the IDOR vulnerability in Infor Global HR. However, specific versions and remediation details are limited.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-60931 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-60931

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-60931 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-60931

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.