CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,232 vulnerabilities with CWE-284
CVE-2026-60942 HIGH
Oracle Service Fulfillment Manager 12.2.3-12.2.15: Authenticated Data Manipulation & Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60941 HIGH
Oracle Service Fulfillment Manager 12.2.3-12.2.15 Authenticated Data Modification & Unauthorized Access
CVSS 8.7
CVE-2026-60940 MEDIUM
Oracle Service Contracts 12.2.3-12.2.15: Authenticated Data Modification & Unauthorized Access via Internal Ops
CVSS 5.7
CVE-2026-60937 LOW
Oracle Labor Distribution 12.2.3-12.2.15 - Authenticated Data Manipulation via HTTP
CVSS 3.1
CVE-2026-60931 HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60929 LOW
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Data Manipulation via HTTP
CVSS 3.1
CVE-2026-60927 HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60926 HIGH
Oracle Public Sector Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60925 HIGH
Oracle Public Sector Payroll 12.2.4-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60918 HIGH
Oracle Shipping Execution 12.2.12-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60917 HIGH
Oracle Inventory Management 12.2.3-12.2.15 - Authenticated Data Creation, Modification, and Access via HTTP
CVSS 8.1
CVE-2026-60912 MEDIUM
Oracle Property Manager 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-60910 HIGH
Oracle Property Manager 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60908 HIGH
Oracle Installed Base 12.2.3-12.2.15 - Authenticated Data Access and Modification via Create Item Instance Component
CVSS 7.1
CVE-2026-60907 MEDIUM
Oracle Installed Base < 12.2.15 - Denial of Service
CVSS 5.0
CVE-2026-60904 HIGH
Oracle Installed Base 12.2.3-12.2.15 - Authenticated Critical Data Creation, Modification, Deletion and Access via HTTP
CVSS 8.1
CVE-2026-60901 HIGH
Oracle Project Intelligence 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60898 HIGH
Oracle Warehouse Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-60897 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-60894 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60893 MEDIUM
Oracle Payroll 12.2.3-12.2.15 - Authenticated Unauthorized Critical Data Access via Internal Operations Component
CVSS 6.5
CVE-2026-60892 MEDIUM
Oracle HRMS (Norway) 12.2.8-12.2.15 - Authenticated Remote Code Execution via Norway Payroll Component
CVSS 6.6
CVE-2026-60890 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60880 CRITICAL
Oracle Work in Process 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60877 HIGH
Oracle Trade Mgmt 12.2.3-12.2.15: Authenticated Data Manipulation & Unauthorized Access via Claim LOV
CVSS 8.1
Details
Vulnerabilities 6,232