CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,232 vulnerabilities with CWE-284
CVE-2026-60749 HIGH
Oracle Assets 12.2.3-12.2.15 - Authenticated Data Manipulation and Unauthorized Data Access via HTTP
CVSS 8.1
CVE-2026-60744 MEDIUM
Oracle Cost Management 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via HTTP
CVSS 6.8
CVE-2026-60741 HIGH
Oracle Cost Management 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via HTTP
CVSS 8.1
CVE-2026-60740 HIGH
Oracle Cash Management 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60739 HIGH
Oracle Field Service 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 7.1
CVE-2026-60738 HIGH
Oracle Installed Base 12.2.3-12.2.15 - Authenticated Remote Takeover via Create Item Instance Component
CVSS 8.8
CVE-2026-60736 HIGH
Oracle E-Business Intelligence 12.2.3-12.2.15: Authenticated Data Modification & Unauthorized Access via Definition
CVSS 8.1
CVE-2026-60735 HIGH
Oracle Sales Offline 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60734 HIGH
Oracle Trading Community 12.2.3-12.2.12 - Authenticated Remote Code Execution via Party Search UI
CVSS 7.2
CVE-2026-60732 HIGH
Oracle iReceivables 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via AR Web Utilities
CVSS 8.1
CVE-2026-60725 HIGH
MySQL Router 8.4.0-8.4.10 and 9.7.0-9.7.1 - Unauthenticated Data Modification and Information Disclosure via HTTP
CVSS 7.4
CVE-2026-60724 MEDIUM
Oracle Customer Interaction History 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-60723 HIGH
Oracle Data Integrator 12.2.1.4.0/14.1.2.0.0: Authenticated Critical Data Access/Modification via Marketplace
CVSS 8.4
CVE-2026-60719 CRITICAL
Oracle BI Publisher - Denial of Service
CVSS 9.9
CVE-2026-60717 MEDIUM
Oracle Complex MRO 12.2.3-12.2.15 Authenticated Data Modification & Info Disclosure via HTTP
CVSS 5.4
CVE-2026-60714 HIGH
Oracle Price Protection 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60713 MEDIUM
Siebel CRM Cloud 22.3-26.5: Authenticated Data Modification & Info Disclosure via Cloud Manager
CVSS 4.4
CVE-2026-60710 HIGH
Oracle EDI Gateway 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60709 MEDIUM
Siebel CRM Cloud 22.3-26.5: Unauthenticated Data Modification & Info Disclosure via Physical Access
CVSS 4.2
CVE-2026-60708 HIGH
Oracle Process Manufacturing Financials 12.2.3-12.2.15: Authenticated Data Modification & Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60706 HIGH
Oracle Process Manufacturing Inventory 12.2.3-12.2.15 Auth Bypass & Data Manipulation via HTTP
CVSS 8.1
CVE-2026-60705 HIGH
Oracle Corporation Siebel Crm Cloud Applications < 26.5 - Denial of Service
CVSS 7.0
CVE-2026-60703 HIGH
Oracle Interaction Blending 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access
CVSS 7.1
CVE-2026-60701 MEDIUM
Oracle Universal Work Queue 12.2.3-12.2.15 - Authenticated Remote Takeover via Work Provider Site Level Administration
CVSS 6.6
CVE-2026-60700 HIGH
Oracle Universal Work Queue 12.2.3-12.2.15: Unauthenticated Data Creation/Deletion/Access via HTTP
CVSS 8.1
Details
Vulnerabilities 6,232