CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,232 vulnerabilities with CWE-284
CVE-2026-60697 MEDIUM
Oracle Site Hub < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60695 MEDIUM
Oracle Enterprise Asset Mgmt 12.2.3-12.2.15: Authenticated Data Modification & Unauthorized Access via Internal Ops
CVSS 5.9
CVE-2026-60694 MEDIUM
Oracle Enterprise Asset Management 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-60692 HIGH
Oracle Enterprise Asset Management 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60691 HIGH
Oracle Content Manager 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60690 HIGH
Siebel CRM Cloud Applications 22.3-26.5 - Authenticated Data Exposure via Siebel Cloud Manager
CVSS 7.7
CVE-2026-60688 MEDIUM
Oracle Scheduler < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60687 MEDIUM
Oracle U.S. Federal Financials 12.2.3-12.2.15 - Unauthenticated Unauthorized Data Access via HTTPS
CVSS 6.8
CVE-2026-60686 HIGH
Oracle U.S. Federal Financials 12.2.3-12.2.15 - Authenticated Data Creation, Deletion and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60685 MEDIUM
Oracle iSupport 12.2.3-12.2.15 - Unauthenticated Cross-Site Request Forgery via HTTP with Impact to Additional Products
CVSS 6.1
CVE-2026-60684 MEDIUM
Oracle Apps Framework 12.2.8-12.2.15: Authenticated Data Modification & Info Disclosure via Upload Attachments
CVSS 4.6
CVE-2026-60683 HIGH
Oracle Process Manufacturing Regulatory Mgmt 12.2.3-12.2.15: Authenticated Critical Data Access via HTTP
CVSS 7.7
CVE-2026-60681 HIGH
Oracle Process Manufacturing Regulatory Management 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60677 HIGH
Oracle Common Application Components < 12.2.15 - Denial of Service
CVSS 8.4
CVE-2026-60676 HIGH
Oracle Applications Framework 12.2.3-12.2.15 - Authenticated Remote Code Execution via Search Bean Component
CVSS 8.8
CVE-2026-60675 HIGH
Oracle Applications Framework 12.2.3-12.2.15 - Authenticated Remote Code Execution via Search Bean Component
CVSS 8.8
CVE-2026-60674 HIGH
Oracle BIEE 8.2.0.0.0/26.01.0.0.0 Unauthenticated Data Access/Modification via HTTP
CVSS 8.2
CVE-2026-60671 HIGH
Oracle Business Intelligence Enterprise Edition - Denial of Service
CVSS 8.6
CVE-2026-60670 HIGH
Oracle Applications Technology Stack 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via Client System Analyzer
CVSS 8.1
CVE-2026-60669 MEDIUM
Oracle Corporation PeopleSoft Enterprise Hcm Global Payroll Mexico - Denial of Service
CVSS 5.9
CVE-2026-60668 HIGH
PeopleSoft HCM 9.2 French Public Sector Component - Unauthenticated Data Access & Modification
CVSS 8.2
CVE-2026-60667 HIGH
Oracle Corporation PeopleSoft Enterprise Hcm Human Resources - Denial of Service
CVSS 7.4
CVE-2026-60666 MEDIUM
PeopleSoft HCM 9.2 Authenticated Data Modification & Info Disclosure via Oracle Net
CVSS 6.8
CVE-2026-60665 HIGH
PeopleSoft Enterprise HCM Global Payroll Switzerland 9.2 Authenticated Data Manipulation & Unauthorized Access via HTTP
CVSS 8.2
CVE-2026-60663 CRITICAL
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 9.9
Details
Vulnerabilities 6,232