CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,232 vulnerabilities with CWE-284
CVE-2026-60788 HIGH
Oracle Sales Offline < 12.2.15 - Denial of Service
CVSS 8.3
CVE-2026-60787 HIGH
Oracle Receivables 12.2.3-12.2.15 - Authenticated Remote Takeover via Internal Operations Component
CVSS 7.2
CVE-2026-60786 HIGH
Oracle Receivables 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 7.2
CVE-2026-60785 HIGH
Oracle iReceivables 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via AR Web Utilities
CVSS 8.1
CVE-2026-60784 HIGH
Oracle Trading Community 12.2.3-12.2.15: Authenticated Data Creation/Deletion & Unauthorized Access via Party Search UI
CVSS 8.1
CVE-2026-60783 HIGH
Oracle iReceivables 12.2.3-12.2.15 - Authenticated Remote Takeover via AR Web Utilities
CVSS 8.8
CVE-2026-60780 HIGH
Oracle Workflow 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via SMTP
CVSS 8.1
CVE-2026-60778 HIGH
Oracle Payments 12.2.3-12.2.15: Authenticated Data Modification & Unauthorized Access via File Transmission
CVSS 8.1
CVE-2026-60777 MEDIUM
Oracle Application Object Library < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60776 MEDIUM
Oracle Application Object Library 12.2.3-12.2.15 - Authenticated Remote Takeover via AOL Generic Loader
CVSS 6.7
CVE-2026-60775 MEDIUM
Oracle Pasta 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 6.7
CVE-2026-60774 HIGH
Oracle Applications Framework 12.2.3-12.2.15 - Authenticated Data Access and Modification via Search Bean Component
CVSS 7.1
CVE-2026-60773 CRITICAL
Oracle AOL 12.2.3-12.2.15: Authenticated Data Creation/Deletion & Unauthorized Access via HTTPS
CVSS 9.6
CVE-2026-60772 HIGH
Oracle Financials Common Modules 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 7.1
CVE-2026-60771 HIGH
Oracle Complex MRO 12.2.3-12.2.15: Authenticated Data Creation/Deletion & Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60770 HIGH
Oracle Application Object Library 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-60768 HIGH
Oracle Apps Framework 12.2.3-12.2.15: Authenticated Data Manipulation & Unauthorized Access via Graph/Chart
CVSS 8.1
CVE-2026-60764 HIGH
Oracle Financials Common Modules 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via HTTP
CVSS 8.1
CVE-2026-60763 HIGH
Oracle Applications Manager 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via RapidClone Command Line
CVSS 8.4
CVE-2026-60762 MEDIUM
Oracle Apps Tech Stack 12.2.3-12.2.15: Authenticated Data Modification & Unauthorized Access
CVSS 5.7
CVE-2026-60761 MEDIUM
Oracle Apps DBA 12.2.3-12.2.15: Authenticated Critical Data Access via Internal Operations
CVSS 6.5
CVE-2026-60760 MEDIUM
Oracle Enterprise Asset Management 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 4.2
CVE-2026-60756 HIGH
Oracle EDI Gateway 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
CVE-2026-60755 HIGH
Oracle Assets 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.2
CVE-2026-60750 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Sensitive Data Exposure via HTTP Request
CVSS 7.7
Details
Vulnerabilities 6,232