CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
6,232 vulnerabilities with CWE-284
CVE-2026-60942
HIGH
Oracle Service Fulfillment Manager 12.2.3-12.2.15: Authenticated Data Manipulation & Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60941
HIGH
Oracle Service Fulfillment Manager 12.2.3-12.2.15 Authenticated Data Modification & Unauthorized Access
CVSS 8.7
CVE-2026-60940
MEDIUM
Oracle Service Contracts 12.2.3-12.2.15: Authenticated Data Modification & Unauthorized Access via Internal Ops
CVSS 5.7
CVE-2026-60937
LOW
Oracle Labor Distribution 12.2.3-12.2.15 - Authenticated Data Manipulation via HTTP
CVSS 3.1
CVE-2026-60931
HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60929
LOW
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Data Manipulation via HTTP
CVSS 3.1
CVE-2026-60927
HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60926
HIGH
Oracle Public Sector Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60925
HIGH
Oracle Public Sector Payroll 12.2.4-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60918
HIGH
Oracle Shipping Execution 12.2.12-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60917
HIGH
Oracle Inventory Management 12.2.3-12.2.15 - Authenticated Data Creation, Modification, and Access via HTTP
CVSS 8.1
CVE-2026-60912
MEDIUM
Oracle Property Manager 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-60910
HIGH
Oracle Property Manager 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60908
HIGH
Oracle Installed Base 12.2.3-12.2.15 - Authenticated Data Access and Modification via Create Item Instance Component
CVSS 7.1
CVE-2026-60907
MEDIUM
Oracle Installed Base < 12.2.15 - Denial of Service
CVSS 5.0
CVE-2026-60904
HIGH
Oracle Installed Base 12.2.3-12.2.15 - Authenticated Critical Data Creation, Modification, Deletion and Access via HTTP
CVSS 8.1
CVE-2026-60901
HIGH
Oracle Project Intelligence 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60898
HIGH
Oracle Warehouse Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-60897
HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-60894
HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60893
MEDIUM
Oracle Payroll 12.2.3-12.2.15 - Authenticated Unauthorized Critical Data Access via Internal Operations Component
CVSS 6.5
CVE-2026-60892
MEDIUM
Oracle HRMS (Norway) 12.2.8-12.2.15 - Authenticated Remote Code Execution via Norway Payroll Component
CVSS 6.6
CVE-2026-60890
HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60880
CRITICAL
Oracle Work in Process 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60877
HIGH
Oracle Trade Mgmt 12.2.3-12.2.15: Authenticated Data Manipulation & Unauthorized Access via Claim LOV
CVSS 8.1
Details
Vulnerabilities
6,232