CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,232 vulnerabilities with CWE-284
CVE-2026-60829 HIGH
Oracle Advanced Outbound Telephony 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60828 HIGH
Oracle Interaction Blending 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60827 HIGH
Oracle iSupport 12.2.3-12.2.15 - Unauthenticated Critical Data Creation/Deletion via HTTP
CVSS 7.4
CVE-2026-60826 MEDIUM
Oracle iSupport 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 6.6
CVE-2026-60825 MEDIUM
Oracle iSupport 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 6.6
CVE-2026-60824 HIGH
Oracle iSupport 12.2.3-12.2.15 - Authenticated Unauthorized Data Access via HTTP
CVSS 7.7
CVE-2026-60823 HIGH
Oracle iSupport 12.2.3-12.2.15 - Unauthenticated Critical Data Access and Modification via HTTP
CVSS 7.4
CVE-2026-60817 HIGH
Oracle iStore 12.2.3-12.2.15 - Authenticated Critical Data Creation, Modification, Deletion and Access via HTTP
CVSS 8.1
CVE-2026-60816 MEDIUM
Oracle iStore 12.2.3-12.2.15 - Authenticated Unauthorized Data Access via Shopping Cart Component
CVSS 5.3
CVE-2026-60815 MEDIUM
Oracle iStore 12.2.3-12.2.15 - Unauthenticated Cross-Site Request Forgery via Shopping Cart Component
CVSS 6.1
CVE-2026-60813 HIGH
Oracle iStore 12.2.3-12.2.15 - Authenticated Remote Takeover via Shopping Cart Component
CVSS 7.2
CVE-2026-60811 MEDIUM
Oracle Supply Chain Trading Connector < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60807 HIGH
Oracle Bills of Material 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP with User Interaction
CVSS 8.0
CVE-2026-60806 HIGH
Oracle Cost Management 12.2.3-12.2.15 - Authenticated Remote Takeover via Costing Transaction Errors
CVSS 7.5
CVE-2026-60805 MEDIUM
Oracle Cost Management < 12.2.15 - Denial of Service
CVSS 6.2
CVE-2026-60804 LOW
Oracle E-Business Intelligence 12.2.3-12.2.15 - Authenticated Data Manipulation via Definition Component
CVSS 2.0
CVE-2026-60802 MEDIUM
Oracle E-Business Intelligence 12.2.3-12.2.15 Unauthenticated CSRF via HTTP (User Interaction)
CVSS 6.1
CVE-2026-60801 MEDIUM
Oracle E-Business Intelligence 12.2.3-12.2.15 - Authenticated Data Manipulation and Unauthorized Data Access via HTTP
CVSS 5.9
CVE-2026-60800 HIGH
Oracle Compensation Workbench 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 7.1
CVE-2026-60799 HIGH
Oracle Compensation Workbench 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 7.1
CVE-2026-60795 MEDIUM
Oracle iSetup 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 6.8
CVE-2026-60794 MEDIUM
Oracle TeleSales 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-60793 HIGH
Oracle TeleSales 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via HTTP
CVSS 8.1
CVE-2026-60790 HIGH
Oracle Sales Offline 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP with Scope Change
CVSS 8.0
CVE-2026-60789 HIGH
Oracle Sales Offline 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
Details
Vulnerabilities 6,232