CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,232 vulnerabilities with CWE-284
CVE-2026-61055 HIGH
PeopleSoft Enterprise SCM Order Management 9.2 - Authenticated Remote Code Execution via Security Component
CVSS 7.8
CVE-2026-61051 MEDIUM
Oracle Concurrent Processing < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-61049 HIGH
Oracle Production Scheduling 12.2.3-12.2.15 Unauth RCE via Physical Network Access & User Interaction
CVSS 7.1
CVE-2026-61047 LOW
Oracle Production Scheduling 12.2.3-12.2.15 - Authenticated Data Manipulation via Internal Operations Component
CVSS 1.9
CVE-2026-61046 MEDIUM
Oracle Production Scheduling 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 6.6
CVE-2026-61044 MEDIUM
Oracle Production Scheduling < 12.2.15 - Denial of Service
CVSS 4.7
CVE-2026-61043 MEDIUM
Oracle Production Scheduling 12.2.3-12.2.15 Authenticated Data Modification & Info Disclosure
CVSS 6.7
CVE-2026-61041 CRITICAL
Oracle Demantra Demand Management 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 9.9
CVE-2026-61039 HIGH
Oracle Advanced Supply Chain Planning 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-61037 HIGH
Oracle Loans 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61036 LOW
Oracle HRMS (Norway) 12.2.3-12.2.15: Authenticated Data Modification & Info Disclosure via Payroll
CVSS 3.8
CVE-2026-61035 HIGH
Oracle Financials for the Americas 12.2.3-12.2.15 - Authenticated Remote Takeover via Internal Operations Component
CVSS 7.2
CVE-2026-61031 HIGH
Oracle Financials Common Country 12.2.3-12.2.15: Authenticated Data Manipulation & Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61030 HIGH
Oracle Process Manufacturing 12.2.3-12.2.15: Authenticated Data Creation/Deletion & Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61027 HIGH
Oracle Cost Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Inventory Costing Component
CVSS 7.2
CVE-2026-61026 HIGH
Oracle iRecruitment 12.2.3-12.2.15 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
CVE-2026-61025 HIGH
Oracle iRecruitment 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 7.2
CVE-2026-61024 HIGH
Oracle iRecruitment 12.2.3-12.2.15 - Authenticated Data Manipulation and Unauthorized Data Access via HTTP
CVSS 8.1
CVE-2026-61020 HIGH
Oracle Customers Online 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61019 HIGH
Oracle Customers Online 12.2.3-12.2.15 - Authenticated Data Creation, Modification, and Access via HTTP
CVSS 8.1
CVE-2026-61013 MEDIUM
Oracle Time and Labor 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 6.6
CVE-2026-61012 HIGH
Oracle Time And Labor < 12.2.15 - Denial of Service
CVSS 7.1
CVE-2026-61010 HIGH
Oracle Process Manufacturing Systems 12.2.3-12.2.15 - Authenticated Remote System Takeover via HTTP
CVSS 8.8
CVE-2026-61009 HIGH
Oracle Process Manufacturing Logistics 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.0
CVE-2026-61005 HIGH
Oracle Process Manufacturing Logistics 12.2.3-12.2.15: Authenticated Data Manipulation & Unauthorized Access via HTTP
CVSS 8.1
Details
Vulnerabilities 6,232