CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,232 vulnerabilities with CWE-284
CVE-2026-61004 HIGH
Oracle Landed Cost Management 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61000 HIGH
Oracle Process Manufacturing Systems 12.2.3-12.2.15 - Authenticated Data Creation, Modification, and Access via HTTP
CVSS 8.1
CVE-2026-60999 CRITICAL
Oracle Data Integrator 14.1.2.0.0 - Unauthenticated Remote Code Execution via Rest Service
CVSS 9.8
CVE-2026-60997 HIGH
Oracle Universal Work Queue 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60989 HIGH
Oracle Advanced Collections 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60988 HIGH
Oracle Project Portfolio Analysis 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60987 HIGH
Oracle Project Portfolio Analysis 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 7.1
CVE-2026-60986 HIGH
Oracle Project Portfolio Analysis 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via HTTP
CVSS 8.1
CVE-2026-60985 HIGH
Oracle Project Portfolio Analysis < 12.2.15 - Denial of Service
CVSS 7.1
CVE-2026-60984 HIGH
Oracle Project Portfolio Analysis 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 7.1
CVE-2026-60982 HIGH
Oracle US Federal HR 12.2.3-12.2.15: Authenticated Data Creation/Deletion & Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60979 HIGH
Oracle Scripting 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
CVE-2026-60978 MEDIUM
Oracle Scripting 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via HTTP
CVSS 6.5
CVE-2026-60974 HIGH
Oracle E-Business Tax 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60972 HIGH
Oracle E-Business Tax 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60966 HIGH
Oracle Public Sector HR 12.2.3-12.2.15: Authenticated Data Creation/Deletion & Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60965 HIGH
Oracle HRMS (France) 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via HTTP
CVSS 8.1
CVE-2026-60963 HIGH
Oracle Treasury 12.2.3-12.2.15 - Authenticated Critical Data Creation, Modification, Deletion and Access via HTTP
CVSS 8.1
CVE-2026-60962 MEDIUM
Oracle Flow Manufacturing 12.2.3-12.2.15 - Cross-Site Request Forgery and Unauthorized Data Access via HTTP
CVSS 5.4
CVE-2026-60960 HIGH
Oracle SDP Number Portability 12.2.3-12.2.15 - Authenticated Remote Takeover via Internal Operations Component
CVSS 8.8
CVE-2026-60959 HIGH
Oracle SDP Number Portability 12.2.3-12.2.15 - Authenticated Data Creation, Deletion and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60953 HIGH
Oracle Telecom Billing Integrator 12.2.3-12.2.15 - Unauthorized Data Access/Modification
CVSS 8.1
CVE-2026-60951 HIGH
Oracle Time and Labor 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60948 HIGH
Oracle Learning Management 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60945 HIGH
Oracle Learning Management 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 7.3
Details
Vulnerabilities 6,232