Description
An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to arbitrarily view the compensation information of other employees via a crafted GET request.
Published: 2026-07-29
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an Insecure Direct Object Reference (IDOR) flaw located in the Employee Compensation View function of Infor Global HR. The IDOR allows an unauthenticated or improperly authorized attacker to construct a special GET request and view the compensation details of any employee within the organization. Because compensation data is highly sensitive, the exploitation of this flaw results in a confidentiality breach, exposing personal financial information applicable to each employee.

Affected Systems

The affected product is Infor Global HR version 11.24.10.01.33. Users running this specific release are at risk; no other vendors or product variants are listed as impacted in the current data.

Risk and Exploitability

With a CVSS score of 7.5 this issue is rated High, reflecting the severity of the confidentiality impact. The EPSS score of less than 1% suggests a low probability of exploitation in the wild at present, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a crafted HTTP GET request to the compensation view endpoint, exploiting the lack of proper authorization checks. In practice, an attacker would need network access to the application and knowledge of valid employee identifiers to benefit from this flaw.

Generated by OpenCVE AI on August 4, 2026 at 12:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install the latest patch for Infor Global HR that resolves the IDOR in the compensation view.
  • Verify that all compensation-related endpoints enforce correct access controls and that only users with appropriate privileges can retrieve data.
  • Enable logging and alerts for anomalous GET requests to the compensation view endpoint to detect exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 12:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Infor
Infor global Human Resources
Vendors & Products Infor
Infor global Human Resources

Tue, 04 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Title Insecure Direct Object Reference Enables Unauthorized Viewing of Employee Compensation in Infor Global HR

Sat, 01 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Insecure Direct Object Reference Enables Unauthorized Viewing of Employee Compensation in Infor Global HR

Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to arbitrarily view the compensation information of other employees via a crafted GET request.
References

Subscriptions

Infor Global Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-29T18:12:36.155Z

Reserved: 2025-09-26T00:00:00.000Z

Link: CVE-2025-60931

cve-icon Vulnrichment

Updated: 2026-07-29T18:12:31.829Z

cve-icon NVD

Status : Deferred

Published: 2026-07-29T17:16:50.367

Modified: 2026-07-30T14:12:18.697

Link: CVE-2025-60931

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:22:32Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key