CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,232 vulnerabilities with CWE-284
CVE-2026-60606 CRITICAL
PeopleSoft Enterprise CC Common App Objects 9.2 - Unauthenticated Data Creation/Modification/Access via HTTP
CVSS 9.1
CVE-2026-60603 HIGH
PeopleSoft Enterprise CS Student Records 9.2.38 - Authenticated Remote Code Execution via Australian Features Component
CVSS 8.8
CVE-2026-60601 MEDIUM
PeopleSoft Enterprise FIN Common Objects 9.2 - Authenticated Data Modification via Security Component
CVSS 4.4
CVE-2026-60599 HIGH
PeopleSoft Enterprise CS Student Records 9.2.38 - Authenticated Data Manipulation via Research Tracking
CVSS 8.1
CVE-2026-60598 HIGH
PeopleSoft Enterprise CS Student Records 9.2.38 - Authenticated Remote Takeover via Research Tracking Component
CVSS 7.5
CVE-2026-60597 HIGH
PeopleSoft Enterprise FIN Cash Mgmt 9.2 - Unauthenticated Critical Data Creation/Modification/Deletion/Access via HTTP
CVSS 8.7
CVE-2026-60594 HIGH
PeopleSoft Enterprise CS Campus Community 9.2.38 - Authenticated RCE via Integration Component
CVSS 8.8
CVE-2026-60593 HIGH
PeopleSoft Enterprise FIN Staffing Front Office 9.2 - Unauthenticated Unauthorized Data Creation and Deletion via HTTP
CVSS 7.5
CVE-2026-60588 MEDIUM
Oracle Enterprise Asset Mgmt 12.2.3-12.2.15: Authenticated Data Modification & Info Disclosure via Work Definition
CVSS 5.4
CVE-2026-60587 MEDIUM
Oracle Project Foundation < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60585 MEDIUM
MySQL 8.0.0-8.0.47, 8.4.0-8.4.1, 9.7.0-9.7.1 Auth RCE via Replication Component
CVSS 6.6
CVE-2026-60584 HIGH
Oracle Transportation Management - Denial of Service
CVSS 7.6
CVE-2026-60583 HIGH
Oracle Transportation Management 6.5.3 - Authenticated Remote Takeover via Install Component
CVSS 8.8
CVE-2026-60582 HIGH
Oracle Enterprise Command Center Framework - Denial of Service
CVSS 8.3
CVE-2026-60581 HIGH
Oracle Enterprise Command Center Framework V16 - Unauthenticated Remote Code Execution via Physical Network Access
CVSS 7.5
CVE-2026-60579 HIGH
Oracle Enterprise Command Center Framework V16 - Unauth Data Modification & Info Disclosure via Physical Access
CVSS 8.0
CVE-2026-60578 HIGH
Oracle Enterprise Command Center Framework V16 - Authenticated Data Access and Modification via HTTP
CVSS 7.6
CVE-2026-60577 HIGH
Oracle Enterprise Command Center Framework V16 - Authenticated Data Access and Modification via HTTP
CVSS 7.1
CVE-2026-60576 HIGH
Oracle Enterprise Command Center Framework V16 - Authenticated Remote Code Execution via HTTP
CVSS 7.2
CVE-2026-60575 MEDIUM
Oracle Workflow < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60573 MEDIUM
Oracle Partner Management < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60572 MEDIUM
Oracle E-Business Suite Integrated Soa Gateway < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60571 MEDIUM
Oracle Sdp Number Portability < 12.2.15 - Denial of Service
CVSS 5.4
CVE-2026-60570 HIGH
Oracle GoldenGate 23.4-23.26.1 - Authenticated Remote Code Execution via Libraries Component
CVSS 7.8
CVE-2026-60565 CRITICAL
Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Runtime Tools Component
CVSS 9.9
Details
Vulnerabilities 6,232