CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,224 vulnerabilities with CWE-284
CVE-2026-62456 HIGH
Oracle HRMS (UK) 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTPS
CVSS 8.2
CVE-2026-62453 MEDIUM
Oracle Hrms (uk) < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62451 HIGH
Oracle Work in Process 12.2.14-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-62447 HIGH
Oracle Trade Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Claim LOV Component
CVSS 8.8
CVE-2026-62445 HIGH
Oracle Order Mgmt 12.2.4-12.2.15: Authenticated Data Modification & Unauthorized Access via Diagnostic Tools
CVSS 8.1
CVE-2026-61338 HIGH
Oracle Contracts Integration 12.2.3-12.2.15 - Authenticated Data Creation, Modification, and Access via HTTP
CVSS 8.1
CVE-2026-61337 HIGH
Oracle Lease and Finance Management 12.2.11-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-61335 HIGH
Oracle Product Workbench 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via HTTP
CVSS 8.1
CVE-2026-61334 HIGH
Oracle Price Protection < 12.2.15 - Improper Access Control
CVSS 7.1
CVE-2026-61333 HIGH
Oracle Product Workbench 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61329 HIGH
Oracle Price Protection 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61328 MEDIUM
Oracle Cost Management < 12.2.15 - Improper Access Control
CVSS 6.6
CVE-2026-61327 HIGH
Oracle Bills of Material 12.2.13-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61325 HIGH
Oracle Advanced Benefits 12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 7.6
CVE-2026-61324 HIGH
Oracle Advanced Benefits 12.2.15 - Authenticated Data Creation and Deletion via HTTP
CVSS 7.7
CVE-2026-61323 MEDIUM
Oracle Advanced Benefits - Improper Access Control
CVSS 6.5
CVE-2026-61322 HIGH
Oracle TeleSales 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-61314 HIGH
Oracle Edi Gateway < 12.2.15 - Improper Access Control
CVSS 7.2
CVE-2026-61312 HIGH
Oracle Product Hub 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP with Scope Change
CVSS 8.5
CVE-2026-61310 HIGH
Oracle Product Hub 12.2.3-12.2.15 - Authenticated Data Creation, Modification, and Access via HTTP
CVSS 8.1
CVE-2026-61309 HIGH
Oracle In-Memory Cost Mgmt for Discrete Industries 12.2.3-12.2.15 - Unauth Data Access via HTTP
CVSS 7.5
CVE-2026-61304 MEDIUM
Oracle Price Protection < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-61301 HIGH
Oracle Process Manufacturing Financials 12.2.3-12.2.15 Authenticated Data Modification & Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61299 HIGH
Oracle Process Manufacturing Logistics < 12.2.15 - Improper Access Control
CVSS 7.1
CVE-2026-61297 HIGH
Oracle Customers Online 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
Details
Vulnerabilities 6,224