CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,232 vulnerabilities with CWE-284
CVE-2026-60520 HIGH
Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0 - Authenticated Data Modification and Unauthorized Data Access via LDAP
CVSS 8.1
CVE-2026-60519 HIGH
Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 - Authenticated Remote Takeover via LDAP
CVSS 7.2
CVE-2026-60503 HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Core Component
CVSS 8.8
CVE-2026-60502 HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via T3/IIOP Protocol
CVSS 7.2
CVE-2026-60501 MEDIUM
Oracle Service Delivery Platform 12.2.1.4.0/14.1.2.0.0 Authenticated Data Modification & Info Disclosure
CVSS 5.2
CVE-2026-60494 HIGH
Oracle Corporation JD Edwards EnterpriseOne General Ledger - Denial of Service
CVSS 7.0
CVE-2026-60491 MEDIUM
Oracle Advanced Inbound Telephony < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-60490 HIGH
JD Edwards EnterpriseOne CRM Foundation 9.2 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60472 HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60471 HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0/14.1.2.0.0 - Unauth RCE via Physical Network Access
CVSS 8.3
CVE-2026-60470 HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0/14.1.2.0.0 - Authenticated Data Manipulation & Unauthorized Access
CVSS 8.7
CVE-2026-60469 HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0/14.1.2.0.0 - Authenticated Data Modification & Unauthorized Access
CVSS 8.7
CVE-2026-60468 HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Data Access and Modification via HTTP
CVSS 7.1
CVE-2026-60466 HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Core Component
CVSS 7.2
CVE-2026-60465 HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via T3/IIOP Protocol
CVSS 8.8
CVE-2026-60464 HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Core Component
CVSS 8.8
CVE-2026-60459 CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Client Bundle
CVSS 9.9
CVE-2026-60457 CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Remote Code Execution via T3 or IIOP Protocol
CVSS 9.9
CVE-2026-60456 CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Client Bundle
CVSS 9.9
CVE-2026-60452 HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Data Access and Modification via HTTP
CVSS 8.5
CVE-2026-60451 HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0 - Authenticated Data Access and Modification via HTTP
CVSS 7.1
CVE-2026-60448 HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Critical Data Access and Modification via HTTP
CVSS 8.7
CVE-2026-60447 CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Client Bundle
CVSS 9.9
CVE-2026-60445 CRITICAL
Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0 - Remote Code Execution via T3 or IIOP Protocol
CVSS 9.9
CVE-2026-60444 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Data Access and Modification via HTTP
CVSS 8.5
Details
Vulnerabilities 6,232