CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
6,232 vulnerabilities with CWE-284
CVE-2026-60788
HIGH
Oracle Sales Offline < 12.2.15 - Denial of Service
CVSS 8.3
CVE-2026-60787
HIGH
Oracle Receivables 12.2.3-12.2.15 - Authenticated Remote Takeover via Internal Operations Component
CVSS 7.2
CVE-2026-60786
HIGH
Oracle Receivables 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 7.2
CVE-2026-60785
HIGH
Oracle iReceivables 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via AR Web Utilities
CVSS 8.1
CVE-2026-60784
HIGH
Oracle Trading Community 12.2.3-12.2.15: Authenticated Data Creation/Deletion & Unauthorized Access via Party Search UI
CVSS 8.1
CVE-2026-60783
HIGH
Oracle iReceivables 12.2.3-12.2.15 - Authenticated Remote Takeover via AR Web Utilities
CVSS 8.8
CVE-2026-60780
HIGH
Oracle Workflow 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via SMTP
CVSS 8.1
CVE-2026-60778
HIGH
Oracle Payments 12.2.3-12.2.15: Authenticated Data Modification & Unauthorized Access via File Transmission
CVSS 8.1
CVE-2026-60777
MEDIUM
Oracle Application Object Library < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60776
MEDIUM
Oracle Application Object Library 12.2.3-12.2.15 - Authenticated Remote Takeover via AOL Generic Loader
CVSS 6.7
CVE-2026-60775
MEDIUM
Oracle Pasta 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 6.7
CVE-2026-60774
HIGH
Oracle Applications Framework 12.2.3-12.2.15 - Authenticated Data Access and Modification via Search Bean Component
CVSS 7.1
CVE-2026-60773
CRITICAL
Oracle AOL 12.2.3-12.2.15: Authenticated Data Creation/Deletion & Unauthorized Access via HTTPS
CVSS 9.6
CVE-2026-60772
HIGH
Oracle Financials Common Modules 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 7.1
CVE-2026-60771
HIGH
Oracle Complex MRO 12.2.3-12.2.15: Authenticated Data Creation/Deletion & Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60770
HIGH
Oracle Application Object Library 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60768
HIGH
Oracle Apps Framework 12.2.3-12.2.15: Authenticated Data Manipulation & Unauthorized Access via Graph/Chart
CVSS 8.1
CVE-2026-60764
HIGH
Oracle Financials Common Modules 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via HTTP
CVSS 8.1
CVE-2026-60763
HIGH
Oracle Applications Manager 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via RapidClone Command Line
CVSS 8.4
CVE-2026-60762
MEDIUM
Oracle Apps Tech Stack 12.2.3-12.2.15: Authenticated Data Modification & Unauthorized Access
CVSS 5.7
CVE-2026-60761
MEDIUM
Oracle Apps DBA 12.2.3-12.2.15: Authenticated Critical Data Access via Internal Operations
CVSS 6.5
CVE-2026-60760
MEDIUM
Oracle Enterprise Asset Management 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 4.2
CVE-2026-60756
HIGH
Oracle EDI Gateway 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
CVE-2026-60755
HIGH
Oracle Assets 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60750
HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Sensitive Data Exposure via HTTP Request
CVSS 7.7
Details
Vulnerabilities
6,232