CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,232 vulnerabilities with CWE-284
CVE-2026-60564 CRITICAL
Oracle WebCenter Portal 12.2.1.4.0/14.1.2.0.0 Authenticated Data Manipulation & Unauthorized Access via HTTP
CVSS 9.6
CVE-2026-60563 HIGH
Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Runtime Tools
CVSS 8.8
CVE-2026-60562 CRITICAL
Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Runtime Tools Component
CVSS 9.9
CVE-2026-60561 CRITICAL
Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Runtime Tools Component
CVSS 9.9
CVE-2026-60560 HIGH
Oracle Identity Manager 12.2.1.4.0/14.1.2.1.0: Authenticated REST WebServices Allow Data Creation/Modification/Access
CVSS 8.1
CVE-2026-60559 HIGH
Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0 - Unauthenticated Unauthorized Data Access via Authentication Engine
CVSS 8.6
CVE-2026-60555 CRITICAL
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60553 HIGH
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Data Modification and Information Disclosure via HTTP
CVSS 8.7
CVE-2026-60552 CRITICAL
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via HTTP
CVSS 9.9
CVE-2026-60550 HIGH
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 8.6
CVE-2026-60547 CRITICAL
Oracle Managed File Transfer 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 9.9
CVE-2026-60542 CRITICAL
Oracle Business Process Management Suite 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via T3/IIOP Protocol
CVSS 9.9
CVE-2026-60541 CRITICAL
Oracle SOA Suite 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Enterprise Scheduling System
CVSS 9.8
CVE-2026-60540 CRITICAL
Oracle SOA Suite 12.2.1.4.0/14.1.2.0.0 Authenticated Data Manipulation & Unauthorized Access
CVSS 9.6
CVE-2026-60536 HIGH
Oracle Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 8.6
CVE-2026-60534 HIGH
Oracle Identity Manager Connector 12.2.1.4.0/14.1.2.1.0 - Authenticated Data Modification & Unauthorized Access
CVSS 7.7
CVE-2026-60533 HIGH
Oracle Identity Manager Connector - Denial of Service
CVSS 8.0
CVE-2026-60529 HIGH
Oracle WebLogic Server 14.1.2.0.0, 15.1.1.0.0 - Authenticated Remote Takeover via Console Component
CVSS 7.2
CVE-2026-60528 HIGH
Oracle WebLogic 14.1.2.0.0/15.1.1.0.0 Authenticated Data Modification & Info Disclosure via Console
CVSS 7.6
CVE-2026-60527 HIGH
Oracle WebLogic Server 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Unauthorized Data Access via Console Component
CVSS 7.1
CVE-2026-60525 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Data Modification and Unauthorized Data Access via HTTP
CVSS 8.2
CVE-2026-60524 CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Remote Code Execution via T3/IIOP Protocol
CVSS 9.9
CVE-2026-60523 HIGH
Oracle WebCenter Content 12.2.1.4.0/14.1.2.0.0 Authenticated Data Modification & Unauthorized Access
CVSS 8.7
CVE-2026-60522 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Data Access and Modification via HTTP
CVSS 7.6
CVE-2026-60521 MEDIUM
Oracle Advanced Pricing 12.2.3-12.2.15 - Unauthenticated Data Modification and Information Disclosure via HTTP
CVSS 6.5
Details
Vulnerabilities 6,232