CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,227 vulnerabilities with CWE-284
CVE-2026-61086 HIGH
PeopleSoft Enterprise SCM Order Management 9.2 - Unauthenticated Unauthorized Data Access via HTTPS
CVSS 7.5
CVE-2026-61085 HIGH
PeopleSoft Enterprise SCM Inventory 9.2 - Unauthenticated Unauthorized Data Access via HTTPS
CVSS 7.5
CVE-2026-61084 MEDIUM
Oracle GoldenGate 19.1-19.30, 21.3-21.21, 23.4-23.26.2 Authenticated Data Modification & Info Disclosure
CVSS 4.4
CVE-2026-61083 MEDIUM
Oracle Performance Management 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-61080 MEDIUM
Oracle Public Sector HR 12.2.3-12.2.15: Authenticated Data Modification & Info Disclosure via HTTP
CVSS 5.4
CVE-2026-61079 MEDIUM
Oracle GoldenGate - Denial of Service
CVSS 5.8
CVE-2026-61078 HIGH
PeopleSoft Enterprise CC Common App Objects 9.2 - Authenticated Data Manipulation & Unauthorized Access via HTTP
CVSS 8.7
CVE-2026-61077 HIGH
PeopleSoft SCM Mobile Inventory 9.2: Authenticated Critical Data Access & Modification via Security Component
CVSS 7.5
CVE-2026-61075 MEDIUM
Oracle Self-Service Human Resources 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-61074 HIGH
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Remote Code Execution via eProcurement Component
CVSS 8.1
CVE-2026-61073 HIGH
PeopleSoft Enterprise FIN Common Objects Brazil 9.1 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
CVE-2026-61072 CRITICAL
PeopleSoft Enterprise FIN Staffing Front Office Brazil 9.1 - Authenticated Remote System Takeover via HTTP
CVSS 9.9
CVE-2026-61071 LOW
PeopleSoft Enterprise FIN Engineering Argentina 9.1 - Authenticated Data Mod & Info Disclosure via HTTP
CVSS 3.3
CVE-2026-61069 MEDIUM
Oracle Corporation PeopleSoft Enterprise Fin General Ledger Argentina - Denial of Service
CVSS 5.9
CVE-2026-61068 HIGH
PeopleSoft Enterprise FIN Billing Argentina 9.1 - Authenticated Remote Takeover via Billing Component
CVSS 7.2
CVE-2026-61062 HIGH
PeopleSoft Enterprise FIN Cash Management 9.2 - Authenticated Remote Code Execution via Cash Management Component
CVSS 8.8
CVE-2026-61060 MEDIUM
Oracle E-Business Suite SES 12.2.3-12.2.15: Authenticated Data Modification & Info Disclosure via Search Engine
CVSS 5.4
CVE-2026-61059 CRITICAL
PeopleSoft Enterprise SCM Order Mgmt 9.2 - Unauthenticated Critical Data Creation, Mod, Deletion & Access via HTTP
CVSS 9.1
CVE-2026-61057 MEDIUM
PeopleSoft Enterprise FIN eSettlements 9.2 - Unauthenticated Data Modification and Information Disclosure via HTTP
CVSS 4.8
CVE-2026-61056 MEDIUM
PeopleSoft Enterprise FIN Grants 9.2 - Unauthenticated Data Modification and Information Disclosure via HTTP
CVSS 4.8
CVE-2026-61055 HIGH
PeopleSoft Enterprise SCM Order Management 9.2 - Authenticated Remote Code Execution via Security Component
CVSS 7.8
CVE-2026-61051 MEDIUM
Oracle Concurrent Processing < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-61049 HIGH
Oracle Production Scheduling 12.2.3-12.2.15 Unauth RCE via Physical Network Access & User Interaction
CVSS 7.1
CVE-2026-61047 LOW
Oracle Production Scheduling 12.2.3-12.2.15 - Authenticated Data Manipulation via Internal Operations Component
CVSS 1.9
CVE-2026-61046 MEDIUM
Oracle Production Scheduling 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 6.6
Details
Vulnerabilities 6,227