CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,224 vulnerabilities with CWE-284
CVE-2026-62574 HIGH
Oracle Java SE 8u491/11.0.31/17.0.19/21.0.11/25.0.3/26.0.1 - Authenticated Remote Code Execution via Install Component
CVSS 7.8
CVE-2026-62567 HIGH
Oracle HRMS (UK) 12.2.3-12.2.15 - Authenticated Unauthorized Data Access via UK Payroll Component
CVSS 7.7
CVE-2026-62565 HIGH
Oracle Hrms (us) < 12.2.15 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 7.1
CVE-2026-62562 MEDIUM
Oracle Hrms (us) < 12.2.15 - Improper Access Control
CVSS 6.5
CVE-2026-62560 HIGH
Oracle HRMS (Norway) 12.2.3-12.2.15 - Authenticated Unauthorized Data Access via HTTP
CVSS 7.7
CVE-2026-62559 MEDIUM
Oracle Hrms (us) < 12.2.15 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 6.8
CVE-2026-62557 HIGH
Oracle Hrms (uk) < 12.2.15 - Improper Access Control
CVSS 7.1
CVE-2026-62556 MEDIUM
Oracle Hrms (us) < 12.2.15 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 6.5
CVE-2026-62549 CRITICAL
Oracle HRMS (UK) 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 9.6
CVE-2026-62546 CRITICAL
Oracle Applications Framework 12.2.8-12.2.15 - Authenticated Remote Code Execution via Web Utilities
CVSS 9.1
CVE-2026-62542 MEDIUM
Oracle Advanced Benefits < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62534 HIGH
Oracle Applications Framework 12.2.11-12.2.15 - Authenticated Remote Code Execution via Web Utilities
CVSS 8.8
CVE-2026-62530 HIGH
Oracle HRMS (France) 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-62528 MEDIUM
Oracle Hcm Configuration Workbench < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62527 MEDIUM
Oracle Learning Management < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62525 MEDIUM
Oracle Quality < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62524 MEDIUM
Oracle Hrms (us) < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62521 HIGH
Oracle HRMS (US) 12.2.7-12.2.15 - Unauthenticated Unauthorized Data Access via US Payroll Component
CVSS 7.5
CVE-2026-62519 MEDIUM
Oracle Succession Planning < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62518 HIGH
Oracle Production Scheduling < 12.2.15 - Denial of Service
CVSS 7.6
CVE-2026-62516 HIGH
Oracle Demantra Demand Management 12.2.3-12.2.15 - Authenticated Remote Takeover via SQL Injection
CVSS 8.8
CVE-2026-62515 HIGH
Oracle Advanced Planning Command Center 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 7.6
CVE-2026-62514 HIGH
Oracle Process Manufacturing Regulatory Management < 12.2.15 - Improper Access Control
CVSS 8.1
CVE-2026-62513 HIGH
Oracle Process Manufacturing Regulatory Management 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 8.5
CVE-2026-62507 MEDIUM
Oracle Time And Labor < 12.2.15 - Improper Access Control
CVSS 5.3
Details
Vulnerabilities 6,224