CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
6,232 vulnerabilities with CWE-284
CVE-2026-60697
MEDIUM
Oracle Site Hub < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60695
MEDIUM
Oracle Enterprise Asset Mgmt 12.2.3-12.2.15: Authenticated Data Modification & Unauthorized Access via Internal Ops
CVSS 5.9
CVE-2026-60694
MEDIUM
Oracle Enterprise Asset Management 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-60692
HIGH
Oracle Enterprise Asset Management 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60691
HIGH
Oracle Content Manager 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60690
HIGH
Siebel CRM Cloud Applications 22.3-26.5 - Authenticated Data Exposure via Siebel Cloud Manager
CVSS 7.7
CVE-2026-60688
MEDIUM
Oracle Scheduler < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60687
MEDIUM
Oracle U.S. Federal Financials 12.2.3-12.2.15 - Unauthenticated Unauthorized Data Access via HTTPS
CVSS 6.8
CVE-2026-60686
HIGH
Oracle U.S. Federal Financials 12.2.3-12.2.15 - Authenticated Data Creation, Deletion and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60685
MEDIUM
Oracle iSupport 12.2.3-12.2.15 - Unauthenticated Cross-Site Request Forgery via HTTP with Impact to Additional Products
CVSS 6.1
CVE-2026-60684
MEDIUM
Oracle Apps Framework 12.2.8-12.2.15: Authenticated Data Modification & Info Disclosure via Upload Attachments
CVSS 4.6
CVE-2026-60683
HIGH
Oracle Process Manufacturing Regulatory Mgmt 12.2.3-12.2.15: Authenticated Critical Data Access via HTTP
CVSS 7.7
CVE-2026-60681
HIGH
Oracle Process Manufacturing Regulatory Management 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60677
HIGH
Oracle Common Application Components < 12.2.15 - Denial of Service
CVSS 8.4
CVE-2026-60676
HIGH
Oracle Applications Framework 12.2.3-12.2.15 - Authenticated Remote Code Execution via Search Bean Component
CVSS 8.8
CVE-2026-60675
HIGH
Oracle Applications Framework 12.2.3-12.2.15 - Authenticated Remote Code Execution via Search Bean Component
CVSS 8.8
CVE-2026-60674
HIGH
Oracle BIEE 8.2.0.0.0/26.01.0.0.0 Unauthenticated Data Access/Modification via HTTP
CVSS 8.2
CVE-2026-60671
HIGH
Oracle Business Intelligence Enterprise Edition - Denial of Service
CVSS 8.6
CVE-2026-60670
HIGH
Oracle Applications Technology Stack 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via Client System Analyzer
CVSS 8.1
CVE-2026-60669
MEDIUM
Oracle Corporation PeopleSoft Enterprise Hcm Global Payroll Mexico - Denial of Service
CVSS 5.9
CVE-2026-60668
HIGH
PeopleSoft HCM 9.2 French Public Sector Component - Unauthenticated Data Access & Modification
CVSS 8.2
CVE-2026-60667
HIGH
Oracle Corporation PeopleSoft Enterprise Hcm Human Resources - Denial of Service
CVSS 7.4
CVE-2026-60666
MEDIUM
PeopleSoft HCM 9.2 Authenticated Data Modification & Info Disclosure via Oracle Net
CVSS 6.8
CVE-2026-60665
HIGH
PeopleSoft Enterprise HCM Global Payroll Switzerland 9.2 Authenticated Data Manipulation & Unauthorized Access via HTTP
CVSS 8.2
CVE-2026-60663
CRITICAL
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 9.9
Details
Vulnerabilities
6,232