CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
6,232 vulnerabilities with CWE-284
CVE-2026-60564
CRITICAL
Oracle WebCenter Portal 12.2.1.4.0/14.1.2.0.0 Authenticated Data Manipulation & Unauthorized Access via HTTP
CVSS 9.6
CVE-2026-60563
HIGH
Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Runtime Tools
CVSS 8.8
CVE-2026-60562
CRITICAL
Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Runtime Tools Component
CVSS 9.9
CVE-2026-60561
CRITICAL
Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Runtime Tools Component
CVSS 9.9
CVE-2026-60560
HIGH
Oracle Identity Manager 12.2.1.4.0/14.1.2.1.0: Authenticated REST WebServices Allow Data Creation/Modification/Access
CVSS 8.1
CVE-2026-60559
HIGH
Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0 - Unauthenticated Unauthorized Data Access via Authentication Engine
CVSS 8.6
CVE-2026-60555
CRITICAL
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60553
HIGH
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Data Modification and Information Disclosure via HTTP
CVSS 8.7
CVE-2026-60552
CRITICAL
Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via HTTP
CVSS 9.9
CVE-2026-60550
HIGH
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 8.6
CVE-2026-60547
CRITICAL
Oracle Managed File Transfer 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 9.9
CVE-2026-60542
CRITICAL
Oracle Business Process Management Suite 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via T3/IIOP Protocol
CVSS 9.9
CVE-2026-60541
CRITICAL
Oracle SOA Suite 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Enterprise Scheduling System
CVSS 9.8
CVE-2026-60540
CRITICAL
Oracle SOA Suite 12.2.1.4.0/14.1.2.0.0 Authenticated Data Manipulation & Unauthorized Access
CVSS 9.6
CVE-2026-60536
HIGH
Oracle Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 8.6
CVE-2026-60534
HIGH
Oracle Identity Manager Connector 12.2.1.4.0/14.1.2.1.0 - Authenticated Data Modification & Unauthorized Access
CVSS 7.7
CVE-2026-60533
HIGH
Oracle Identity Manager Connector - Denial of Service
CVSS 8.0
CVE-2026-60529
HIGH
Oracle WebLogic Server 14.1.2.0.0, 15.1.1.0.0 - Authenticated Remote Takeover via Console Component
CVSS 7.2
CVE-2026-60528
HIGH
Oracle WebLogic 14.1.2.0.0/15.1.1.0.0 Authenticated Data Modification & Info Disclosure via Console
CVSS 7.6
CVE-2026-60527
HIGH
Oracle WebLogic Server 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Unauthorized Data Access via Console Component
CVSS 7.1
CVE-2026-60525
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Data Modification and Unauthorized Data Access via HTTP
CVSS 8.2
CVE-2026-60524
CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Remote Code Execution via T3/IIOP Protocol
CVSS 9.9
CVE-2026-60523
HIGH
Oracle WebCenter Content 12.2.1.4.0/14.1.2.0.0 Authenticated Data Modification & Unauthorized Access
CVSS 8.7
CVE-2026-60522
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Data Access and Modification via HTTP
CVSS 7.6
CVE-2026-60521
MEDIUM
Oracle Advanced Pricing 12.2.3-12.2.15 - Unauthenticated Data Modification and Information Disclosure via HTTP
CVSS 6.5
Details
Vulnerabilities
6,232