CWE-200

High likelihood

Exposure of Sensitive Information to an Unauthorized Actor

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

10,504 vulnerabilities with CWE-200
CVE-2026-60554 HIGH
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
CVE-2026-60553 HIGH
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Data Modification and Information Disclosure via HTTP
CVSS 8.7
CVE-2026-60552 CRITICAL
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via HTTP
CVSS 9.9
CVE-2026-60551 CRITICAL
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60550 HIGH
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 8.6
CVE-2026-60548 HIGH
Oracle SOA Suite 12.2.1.4.0/14.1.2.0.0: Authenticated Critical Data Access via Integration Business Insight
CVSS 7.7
CVE-2026-60449 HIGH
Oracle WebCenter Content 12.2.1.4.0/14.1.2.0.0 Unauthenticated Unauthorized Data Access
CVSS 7.1
CVE-2026-60440 HIGH
Oracle Service Delivery Platform 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Data Exposure via Messaging Enabler
CVSS 7.7
CVE-2026-60431 HIGH
Oracle HTTP Server 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Sensitive Data Exposure via mod_proxy
CVSS 8.6
CVE-2026-60408 MEDIUM
TimesTen In-Memory Database 26.1.1.1.0 - Authenticated Information Disclosure via Kubernetes Operator
CVSS 4.3
CVE-2026-60405 LOW
TimesTen In-Memory Database 26.1.1.1.0 - Authenticated Information Disclosure via Kubernetes Operator
CVSS 3.8
CVE-2026-60395 MEDIUM
Oracle GoldenGate 19.1-19.30, 21.3-21.21, 23.4-23.26.1 Authenticated Info Disclosure via Admin Server
CVSS 4.3
CVE-2026-60394 MEDIUM
Oracle GoldenGate 21.3-21.21 and 23.4-23.26.1 - Unauthenticated Information Disclosure via Admin Server Executable
CVSS 5.3
CVE-2026-60354 LOW
Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Information Disclosure via HTTP
CVSS 3.7
CVE-2026-60352 LOW
Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Information Disclosure via ADF Faces
CVSS 3.7
CVE-2026-60350 MEDIUM
Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Unauthorized Data Access via ADF Faces
CVSS 6.5
CVE-2026-60349 MEDIUM
Oracle JDeveloper - Denial of Service
CVSS 5.9
CVE-2026-60339 LOW
Oracle Project Manufacturing V16 - Authenticated Information Disclosure via PJM Command Center
CVSS 3.1
CVE-2026-60318 LOW
Oracle Data Integrator 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Information Disclosure via Patchset Assistant
CVSS 3.3
CVE-2026-60315 HIGH
Oracle Corporation MySQL Server - Denial of Service
CVSS 8.2
CVE-2026-60307 MEDIUM
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Authenticated Information Disclosure via HTTP
CVSS 4.3
CVE-2026-60293 HIGH
Oracle WebLogic Server 12.2.1.4.0/14.1.1-2.0.0/15.1.1.0.0 - Unauthenticated Data Access via WLS Web Services
CVSS 8.6
CVE-2026-60283 MEDIUM
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Information Disclosure via HTTP
CVSS 5.3
CVE-2026-60266 MEDIUM
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Sensitive Data Exposure via TLS
CVSS 5.9
CVE-2026-60264 CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP/2
CVSS 9.8
Details
Vulnerabilities 10,504
Exploit Likelihood High