CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,224 vulnerabilities with CWE-284
CVE-2026-62505 MEDIUM
Oracle Time And Labor < 12.2.15 - Improper Access Control
CVSS 6.1
CVE-2026-62504 HIGH
Oracle Time and Labor 12.2.3-12.2.15 - Authenticated Critical Data Creation, Modification, Deletion and Access via HTTP
CVSS 8.1
CVE-2026-62503 MEDIUM
Oracle Time And Labor < 12.2.15 - Denial of Service
CVSS 6.7
CVE-2026-62497 HIGH
Oracle Flow Manufacturing 12.2.13-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-62495 HIGH
Oracle Process Manufacturing Process Execution 12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 7.5
CVE-2026-62494 HIGH
Oracle Time and Labor 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-62493 HIGH
Oracle Purchasing 12.2.11-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-62489 MEDIUM
Oracle Contracts Integration < 12.2.15 - Improper Access Control
CVSS 4.2
CVE-2026-62488 MEDIUM
Oracle Contracts Integration < 12.2.15 - Improper Access Control
CVSS 6.5
CVE-2026-62486 MEDIUM
Oracle Contracts Integration < 12.2.15 - Denial of Service
CVSS 5.0
CVE-2026-62484 MEDIUM
Oracle Contracts Integration < 12.2.15 - Improper Access Control
CVSS 5.9
CVE-2026-62483 MEDIUM
Oracle Project Contracts < 12.2.15 - Improper Access Control
CVSS 4.3
CVE-2026-62482 MEDIUM
Oracle Public Sector Financials < 12.2.15 - Improper Access Control
CVSS 5.4
CVE-2026-62480 MEDIUM
Oracle Public Sector Financials < 12.2.15 - Improper Access Control
CVSS 6.5
CVE-2026-62479 MEDIUM
Oracle Public Sector Financials < 12.2.15 - Improper Access Control
CVSS 5.4
CVE-2026-62478 HIGH
Oracle Public Sector Financials 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62476 HIGH
Oracle Public Sector Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-62474 MEDIUM
Oracle Lease And Finance Management < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62473 HIGH
Oracle Installed Base < 12.2.15 - Denial of Service
CVSS 8.3
CVE-2026-62472 HIGH
Oracle Installed Base 12.2.4-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-62469 HIGH
Oracle Human Resources < 12.2.15 - Improper Access Control
CVSS 7.1
CVE-2026-62468 HIGH
Oracle Human Resources 12.2.14-12.2.15 Authenticated Data Manipulation & Unauthorized Access via ECC
CVSS 8.1
CVE-2026-62466 HIGH
Oracle Human Resources < 12.2.15 - Improper Access Control
CVSS 7.2
CVE-2026-62465 MEDIUM
Oracle Hrms (us) < 12.2.15 - Denial of Service
CVSS 6.6
CVE-2026-62464 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
Details
Vulnerabilities 6,224