CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
6,224 vulnerabilities with CWE-284
CVE-2026-62574
HIGH
Oracle Java SE 8u491/11.0.31/17.0.19/21.0.11/25.0.3/26.0.1 - Authenticated Remote Code Execution via Install Component
CVSS 7.8
CVE-2026-62567
HIGH
Oracle HRMS (UK) 12.2.3-12.2.15 - Authenticated Unauthorized Data Access via UK Payroll Component
CVSS 7.7
CVE-2026-62565
HIGH
Oracle Hrms (us) < 12.2.15 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 7.1
CVE-2026-62562
MEDIUM
Oracle Hrms (us) < 12.2.15 - Improper Access Control
CVSS 6.5
CVE-2026-62560
HIGH
Oracle HRMS (Norway) 12.2.3-12.2.15 - Authenticated Unauthorized Data Access via HTTP
CVSS 7.7
CVE-2026-62559
MEDIUM
Oracle Hrms (us) < 12.2.15 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 6.8
CVE-2026-62557
HIGH
Oracle Hrms (uk) < 12.2.15 - Improper Access Control
CVSS 7.1
CVE-2026-62556
MEDIUM
Oracle Hrms (us) < 12.2.15 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 6.5
CVE-2026-62549
CRITICAL
Oracle HRMS (UK) 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 9.6
CVE-2026-62546
CRITICAL
Oracle Applications Framework 12.2.8-12.2.15 - Authenticated Remote Code Execution via Web Utilities
CVSS 9.1
CVE-2026-62542
MEDIUM
Oracle Advanced Benefits < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62534
HIGH
Oracle Applications Framework 12.2.11-12.2.15 - Authenticated Remote Code Execution via Web Utilities
CVSS 8.8
CVE-2026-62530
HIGH
Oracle HRMS (France) 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-62528
MEDIUM
Oracle Hcm Configuration Workbench < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62527
MEDIUM
Oracle Learning Management < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62525
MEDIUM
Oracle Quality < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62524
MEDIUM
Oracle Hrms (us) < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62521
HIGH
Oracle HRMS (US) 12.2.7-12.2.15 - Unauthenticated Unauthorized Data Access via US Payroll Component
CVSS 7.5
CVE-2026-62519
MEDIUM
Oracle Succession Planning < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62518
HIGH
Oracle Production Scheduling < 12.2.15 - Denial of Service
CVSS 7.6
CVE-2026-62516
HIGH
Oracle Demantra Demand Management 12.2.3-12.2.15 - Authenticated Remote Takeover via SQL Injection
CVSS 8.8
CVE-2026-62515
HIGH
Oracle Advanced Planning Command Center 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 7.6
CVE-2026-62514
HIGH
Oracle Process Manufacturing Regulatory Management < 12.2.15 - Improper Access Control
CVSS 8.1
CVE-2026-62513
HIGH
Oracle Process Manufacturing Regulatory Management 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 8.5
CVE-2026-62507
MEDIUM
Oracle Time And Labor < 12.2.15 - Improper Access Control
CVSS 5.3
Details
Vulnerabilities
6,224