CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
6,232 vulnerabilities with CWE-284
CVE-2026-60749
HIGH
Oracle Assets 12.2.3-12.2.15 - Authenticated Data Manipulation and Unauthorized Data Access via HTTP
CVSS 8.1
CVE-2026-60744
MEDIUM
Oracle Cost Management 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via HTTP
CVSS 6.8
CVE-2026-60741
HIGH
Oracle Cost Management 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via HTTP
CVSS 8.1
CVE-2026-60740
HIGH
Oracle Cash Management 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60739
HIGH
Oracle Field Service 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 7.1
CVE-2026-60738
HIGH
Oracle Installed Base 12.2.3-12.2.15 - Authenticated Remote Takeover via Create Item Instance Component
CVSS 8.8
CVE-2026-60736
HIGH
Oracle E-Business Intelligence 12.2.3-12.2.15: Authenticated Data Modification & Unauthorized Access via Definition
CVSS 8.1
CVE-2026-60735
HIGH
Oracle Sales Offline 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60734
HIGH
Oracle Trading Community 12.2.3-12.2.12 - Authenticated Remote Code Execution via Party Search UI
CVSS 7.2
CVE-2026-60732
HIGH
Oracle iReceivables 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via AR Web Utilities
CVSS 8.1
CVE-2026-60725
HIGH
MySQL Router 8.4.0-8.4.10 and 9.7.0-9.7.1 - Unauthenticated Data Modification and Information Disclosure via HTTP
CVSS 7.4
CVE-2026-60724
MEDIUM
Oracle Customer Interaction History 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-60723
HIGH
Oracle Data Integrator 12.2.1.4.0/14.1.2.0.0: Authenticated Critical Data Access/Modification via Marketplace
CVSS 8.4
CVE-2026-60719
CRITICAL
Oracle BI Publisher - Denial of Service
CVSS 9.9
CVE-2026-60717
MEDIUM
Oracle Complex MRO 12.2.3-12.2.15 Authenticated Data Modification & Info Disclosure via HTTP
CVSS 5.4
CVE-2026-60714
HIGH
Oracle Price Protection 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60713
MEDIUM
Siebel CRM Cloud 22.3-26.5: Authenticated Data Modification & Info Disclosure via Cloud Manager
CVSS 4.4
CVE-2026-60710
HIGH
Oracle EDI Gateway 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60709
MEDIUM
Siebel CRM Cloud 22.3-26.5: Unauthenticated Data Modification & Info Disclosure via Physical Access
CVSS 4.2
CVE-2026-60708
HIGH
Oracle Process Manufacturing Financials 12.2.3-12.2.15: Authenticated Data Modification & Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60706
HIGH
Oracle Process Manufacturing Inventory 12.2.3-12.2.15 Auth Bypass & Data Manipulation via HTTP
CVSS 8.1
CVE-2026-60705
HIGH
Oracle Corporation Siebel Crm Cloud Applications < 26.5 - Denial of Service
CVSS 7.0
CVE-2026-60703
HIGH
Oracle Interaction Blending 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access
CVSS 7.1
CVE-2026-60701
MEDIUM
Oracle Universal Work Queue 12.2.3-12.2.15 - Authenticated Remote Takeover via Work Provider Site Level Administration
CVSS 6.6
CVE-2026-60700
HIGH
Oracle Universal Work Queue 12.2.3-12.2.15: Unauthenticated Data Creation/Deletion/Access via HTTP
CVSS 8.1
Details
Vulnerabilities
6,232