CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
6,232 vulnerabilities with CWE-284
CVE-2026-60829
HIGH
Oracle Advanced Outbound Telephony 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60828
HIGH
Oracle Interaction Blending 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60827
HIGH
Oracle iSupport 12.2.3-12.2.15 - Unauthenticated Critical Data Creation/Deletion via HTTP
CVSS 7.4
CVE-2026-60826
MEDIUM
Oracle iSupport 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 6.6
CVE-2026-60825
MEDIUM
Oracle iSupport 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 6.6
CVE-2026-60824
HIGH
Oracle iSupport 12.2.3-12.2.15 - Authenticated Unauthorized Data Access via HTTP
CVSS 7.7
CVE-2026-60823
HIGH
Oracle iSupport 12.2.3-12.2.15 - Unauthenticated Critical Data Access and Modification via HTTP
CVSS 7.4
CVE-2026-60817
HIGH
Oracle iStore 12.2.3-12.2.15 - Authenticated Critical Data Creation, Modification, Deletion and Access via HTTP
CVSS 8.1
CVE-2026-60816
MEDIUM
Oracle iStore 12.2.3-12.2.15 - Authenticated Unauthorized Data Access via Shopping Cart Component
CVSS 5.3
CVE-2026-60815
MEDIUM
Oracle iStore 12.2.3-12.2.15 - Unauthenticated Cross-Site Request Forgery via Shopping Cart Component
CVSS 6.1
CVE-2026-60813
HIGH
Oracle iStore 12.2.3-12.2.15 - Authenticated Remote Takeover via Shopping Cart Component
CVSS 7.2
CVE-2026-60811
MEDIUM
Oracle Supply Chain Trading Connector < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60807
HIGH
Oracle Bills of Material 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP with User Interaction
CVSS 8.0
CVE-2026-60806
HIGH
Oracle Cost Management 12.2.3-12.2.15 - Authenticated Remote Takeover via Costing Transaction Errors
CVSS 7.5
CVE-2026-60805
MEDIUM
Oracle Cost Management < 12.2.15 - Denial of Service
CVSS 6.2
CVE-2026-60804
LOW
Oracle E-Business Intelligence 12.2.3-12.2.15 - Authenticated Data Manipulation via Definition Component
CVSS 2.0
CVE-2026-60802
MEDIUM
Oracle E-Business Intelligence 12.2.3-12.2.15 Unauthenticated CSRF via HTTP (User Interaction)
CVSS 6.1
CVE-2026-60801
MEDIUM
Oracle E-Business Intelligence 12.2.3-12.2.15 - Authenticated Data Manipulation and Unauthorized Data Access via HTTP
CVSS 5.9
CVE-2026-60800
HIGH
Oracle Compensation Workbench 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 7.1
CVE-2026-60799
HIGH
Oracle Compensation Workbench 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 7.1
CVE-2026-60795
MEDIUM
Oracle iSetup 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 6.8
CVE-2026-60794
MEDIUM
Oracle TeleSales 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-60793
HIGH
Oracle TeleSales 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via HTTP
CVSS 8.1
CVE-2026-60790
HIGH
Oracle Sales Offline 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP with Scope Change
CVSS 8.0
CVE-2026-60789
HIGH
Oracle Sales Offline 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
Details
Vulnerabilities
6,232