CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
6,232 vulnerabilities with CWE-284
CVE-2026-60875
HIGH
Oracle Trade Mgmt 12.2.3-12.2.15: Authenticated Data Manipulation & Unauthorized Access via Claim LOV
CVSS 8.1
CVE-2026-60872
HIGH
Oracle Order Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Product Diagnostic Tools
CVSS 8.8
CVE-2026-60871
HIGH
Oracle Risk Management 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60870
HIGH
Oracle Advanced Pricing 12.2.3-12.2.15 - Authenticated Data Access and Modification via Pricing Installation Component
CVSS 7.1
CVE-2026-60868
HIGH
Oracle Advanced Pricing 12.2.14-12.2.15 - Authenticated Data Access and Modification via Pricing Installation Component
CVSS 7.1
CVE-2026-60867
HIGH
Oracle Advanced Pricing 12.2.3-12.2.15: Authenticated Data Modification & Unauthorized Access via Pricing Install
CVSS 8.1
CVE-2026-60864
MEDIUM
Oracle Order Management 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 6.4
CVE-2026-60863
HIGH
Oracle Advanced Pricing 12.2.3-12.2.15 - Authenticated Remote Takeover via Pricing Installation Component
CVSS 8.8
CVE-2026-60862
MEDIUM
Oracle Order Management 12.2.3-12.2.15 - Authenticated Unauthorized Critical Data Access via Product Diagnostic Tools
CVSS 6.8
CVE-2026-60859
HIGH
Oracle Quoting 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 7.5
CVE-2026-60857
HIGH
Oracle Contracts Integration 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60855
HIGH
Oracle Quality 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60854
HIGH
Oracle Quality < 12.2.15 - Denial of Service
CVSS 8.2
CVE-2026-60852
HIGH
Oracle Lease and Finance Mgmt 12.2.3-12.2.15: Authenticated Data Manipulation & Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60848
HIGH
Oracle Project Contracts 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60847
LOW
Oracle Order Entry < 12.2.15 - Denial of Service
CVSS 3.4
CVE-2026-60846
MEDIUM
Oracle Mobile Application Server < 12.2.15 - Denial of Service
CVSS 6.7
CVE-2026-60845
HIGH
Oracle Mobile Application Server 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 7.2
CVE-2026-60844
HIGH
Oracle Customer Support 12.2.3-12.2.15 Auth Bypass via Update Service Request Leads to Data Modification/Access
CVSS 8.1
CVE-2026-60843
MEDIUM
Oracle Citizen Interaction Center 12.2.3-12.2.15: Authenticated Data Manipulation & Unauthorized Access via Internal Ops
CVSS 6.5
CVE-2026-60840
HIGH
Oracle Demand Signal Repository 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via SQL
CVSS 8.1
CVE-2026-60838
HIGH
Oracle Price Protection 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 7.1
CVE-2026-60837
HIGH
Oracle Price Protection 12.2.3-12.2.15: Authenticated Critical Data Manipulation & Unauthorized Access via Internal Ops
CVSS 8.4
CVE-2026-60834
HIGH
Oracle Solaris 11.4 - Authenticated Data Access and Modification via RAD Network Service
CVSS 7.1
CVE-2026-60832
MEDIUM
Oracle Interaction Blending < 12.2.15 - Denial of Service
CVSS 4.1
Details
Vulnerabilities
6,232