CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,232 vulnerabilities with CWE-284
CVE-2026-60875 HIGH
Oracle Trade Mgmt 12.2.3-12.2.15: Authenticated Data Manipulation & Unauthorized Access via Claim LOV
CVSS 8.1
CVE-2026-60872 HIGH
Oracle Order Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Product Diagnostic Tools
CVSS 8.8
CVE-2026-60871 HIGH
Oracle Risk Management 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60870 HIGH
Oracle Advanced Pricing 12.2.3-12.2.15 - Authenticated Data Access and Modification via Pricing Installation Component
CVSS 7.1
CVE-2026-60868 HIGH
Oracle Advanced Pricing 12.2.14-12.2.15 - Authenticated Data Access and Modification via Pricing Installation Component
CVSS 7.1
CVE-2026-60867 HIGH
Oracle Advanced Pricing 12.2.3-12.2.15: Authenticated Data Modification & Unauthorized Access via Pricing Install
CVSS 8.1
CVE-2026-60864 MEDIUM
Oracle Order Management 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 6.4
CVE-2026-60863 HIGH
Oracle Advanced Pricing 12.2.3-12.2.15 - Authenticated Remote Takeover via Pricing Installation Component
CVSS 8.8
CVE-2026-60862 MEDIUM
Oracle Order Management 12.2.3-12.2.15 - Authenticated Unauthorized Critical Data Access via Product Diagnostic Tools
CVSS 6.8
CVE-2026-60859 HIGH
Oracle Quoting 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 7.5
CVE-2026-60857 HIGH
Oracle Contracts Integration 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60855 HIGH
Oracle Quality 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60854 HIGH
Oracle Quality < 12.2.15 - Denial of Service
CVSS 8.2
CVE-2026-60852 HIGH
Oracle Lease and Finance Mgmt 12.2.3-12.2.15: Authenticated Data Manipulation & Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60848 HIGH
Oracle Project Contracts 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60847 LOW
Oracle Order Entry < 12.2.15 - Denial of Service
CVSS 3.4
CVE-2026-60846 MEDIUM
Oracle Mobile Application Server < 12.2.15 - Denial of Service
CVSS 6.7
CVE-2026-60845 HIGH
Oracle Mobile Application Server 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 7.2
CVE-2026-60844 HIGH
Oracle Customer Support 12.2.3-12.2.15 Auth Bypass via Update Service Request Leads to Data Modification/Access
CVSS 8.1
CVE-2026-60843 MEDIUM
Oracle Citizen Interaction Center 12.2.3-12.2.15: Authenticated Data Manipulation & Unauthorized Access via Internal Ops
CVSS 6.5
CVE-2026-60840 HIGH
Oracle Demand Signal Repository 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via SQL
CVSS 8.1
CVE-2026-60838 HIGH
Oracle Price Protection 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 7.1
CVE-2026-60837 HIGH
Oracle Price Protection 12.2.3-12.2.15: Authenticated Critical Data Manipulation & Unauthorized Access via Internal Ops
CVSS 8.4
CVE-2026-60834 HIGH
Oracle Solaris 11.4 - Authenticated Data Access and Modification via RAD Network Service
CVSS 7.1
CVE-2026-60832 MEDIUM
Oracle Interaction Blending < 12.2.15 - Denial of Service
CVSS 4.1
Details
Vulnerabilities 6,232