CWE-200

High likelihood

Exposure of Sensitive Information to an Unauthorized Actor

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

10,504 vulnerabilities with CWE-200
CVE-2026-60922 LOW
Oracle iSupplier Portal 12.2.3-12.2.15 - Authenticated Information Disclosure via HTTP
CVSS 3.1
CVE-2026-60919 LOW
Oracle iSupplier Portal 12.2.3-12.2.15 - Unauthenticated Information Disclosure via HTTP
CVSS 3.7
CVE-2026-60913 LOW
Oracle Property Manager 12.2.3-12.2.15 - Authenticated Information Disclosure via Internal Operations Component
CVSS 1.9
CVE-2026-60899 MEDIUM
Oracle HCM Config Workbench 12.2.3-12.2.15: Authenticated Unauthorized Data Access via Rapid Implementation
CVSS 6.5
CVE-2026-60896 LOW
Oracle Work IN Process < 12.2.15 - Denial of Service
CVSS 3.6
CVE-2026-60891 LOW
Oracle Work in Process 12.2.3-12.2.15 - Authenticated Information Disclosure via Local Access
CVSS 1.9
CVE-2026-60888 MEDIUM
Oracle Work in Process 12.2.3-12.2.15 - Authenticated Sensitive Data Exposure via HTTP
CVSS 5.3
CVE-2026-60886 HIGH
Oracle Work in Process 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP with User Interaction
CVSS 7.6
CVE-2026-60864 MEDIUM
Oracle Order Management 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 6.4
CVE-2026-60844 HIGH
Oracle Customer Support 12.2.3-12.2.15 Auth Bypass via Update Service Request Leads to Data Modification/Access
CVSS 8.1
CVE-2026-60835 MEDIUM
Oracle Price Protection 12.2.3-12.2.15 - Authenticated Sensitive Data Exposure via HTTP
CVSS 6.5
CVE-2026-60812 MEDIUM
Oracle Supply Chain Trading Connector 12.2.3-12.2.15 - Authenticated Sensitive Data Exposure via Collaboration History
CVSS 6.5
CVE-2026-60705 HIGH
Oracle Corporation Siebel Crm Cloud Applications < 26.5 - Denial of Service
CVSS 7.0
CVE-2026-60687 MEDIUM
Oracle U.S. Federal Financials 12.2.3-12.2.15 - Unauthenticated Unauthorized Data Access via HTTPS
CVSS 6.8
CVE-2026-60673 MEDIUM
Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 - Unauthorized Data Access via XML Services
CVSS 6.5
CVE-2026-60647 HIGH
Oracle WebCenter Content - Denial of Service
CVSS 7.1
CVE-2026-60620 MEDIUM
Oracle Corporation JD Edwards EnterpriseOne Configurator - Denial of Service
CVSS 6.4
CVE-2026-60611 MEDIUM
PeopleSoft Enterprise CS Campus Community 9.2.38 - Unauthenticated Information Disclosure via HTTP
CVSS 5.3
CVE-2026-60610 MEDIUM
PeopleSoft Enterprise CS Campus Community 9.2.38 - Unauthenticated Unauthorized Data Access via HTTPS
CVSS 5.9
CVE-2026-60609 MEDIUM
PeopleSoft Enterprise CS Campus Community 9.2.38 - Authenticated Unauthorized Data Access via Communication Component
CVSS 6.5
CVE-2026-60607 MEDIUM
PeopleSoft Enterprise CS Financial Aid 9.2.38 - Authenticated Unauthorized Data Access via FM Need Analysis Calculator
CVSS 5.5
CVE-2026-60558 HIGH
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
CVE-2026-60557 MEDIUM
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Sensitive Data Exposure via HTTP with User Interaction
CVSS 6.5
CVE-2026-60556 HIGH
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 8.6
CVE-2026-60555 CRITICAL
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
Details
Vulnerabilities 10,504
Exploit Likelihood High