PatchSiren cyber security CVE debrief
CVE-2025-60931 Infor CVE debrief
An Insecure Direct Object Reference (IDOR) vulnerability exists in Infor Global HR v11.24.10.01.33, allowing unauthorized attackers to view compensation information of other employees via crafted GET requests. This IDOR vulnerability can lead to potential unauthorized access to sensitive employee compensation information. Defenders should verify exposure, restrict access, and monitor for suspicious requests. The CVE record and NVD entry provide details on the IDOR vulnerability in Infor Global HR. However, specific versions and remediation details are limited. To address this vulnerability, defenders should prioritize verifying exposure of Infor Global HR v11.24.10.01.33 to this ID
- Vendor
- Infor
- Product
- Global HR
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-29
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-07-29
- Advisory updated
- 2026-10-05
Who should care
Defenders responsible for Infor Global HR deployments should assess exposure to this IDOR vulnerability and take steps to restrict access to employee compensation views.
Why it matters
This IDOR vulnerability in Infor Global HR v11.24.10.01.33 allows unauthorized access to employee compensation information. Defenders should verify exposure, restrict access, and monitor for suspicious requests.
- Potential unauthorized access to sensitive employee compensation information
- Possible data exposure through crafted GET requests
- Need for verification of Infor Global HR version exposure
- Potential impact on employee data confidentiality
Technical summary
The Infor Global HR v11.24.10.01.33 contains an Insecure Direct Object Reference (IDOR) vulnerability in the Employee Compensation View function. This allows unauthorized attackers to view compensation information of other employees via crafted GET requests.
Defensive priority
Defenders should prioritize verifying exposure of Infor Global HR v11.24.10.01.33 to this IDOR vulnerability and restrict access to employee compensation views.
Recommended defensive actions
- Verify Infor Global HR v11.24.10.01.33 exposure to this IDOR vulnerability
- Restrict access to employee compensation views
- Monitor for suspicious GET requests to employee compensation pages
Evidence notes
The CVE record and NVD entry provide details on the IDOR vulnerability in Infor Global HR. However, specific versions and remediation details are limited.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-60931 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-60931
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-60931 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-60931
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.offsecguy.com/cve/infor/vulnerability/insecure-direct-object-references-idor
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.