CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
6,224 vulnerabilities with CWE-284
CVE-2026-62456
HIGH
Oracle HRMS (UK) 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTPS
CVSS 8.2
CVE-2026-62453
MEDIUM
Oracle Hrms (uk) < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-62451
HIGH
Oracle Work in Process 12.2.14-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-62447
HIGH
Oracle Trade Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Claim LOV Component
CVSS 8.8
CVE-2026-62445
HIGH
Oracle Order Mgmt 12.2.4-12.2.15: Authenticated Data Modification & Unauthorized Access via Diagnostic Tools
CVSS 8.1
CVE-2026-61338
HIGH
Oracle Contracts Integration 12.2.3-12.2.15 - Authenticated Data Creation, Modification, and Access via HTTP
CVSS 8.1
CVE-2026-61337
HIGH
Oracle Lease and Finance Management 12.2.11-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 7.5
CVE-2026-61335
HIGH
Oracle Product Workbench 12.2.3-12.2.15 - Authenticated Data Modification and Unauthorized Data Access via HTTP
CVSS 8.1
CVE-2026-61334
HIGH
Oracle Price Protection < 12.2.15 - Improper Access Control
CVSS 7.1
CVE-2026-61333
HIGH
Oracle Product Workbench 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61329
HIGH
Oracle Price Protection 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61328
MEDIUM
Oracle Cost Management < 12.2.15 - Improper Access Control
CVSS 6.6
CVE-2026-61327
HIGH
Oracle Bills of Material 12.2.13-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61325
HIGH
Oracle Advanced Benefits 12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 7.6
CVE-2026-61324
HIGH
Oracle Advanced Benefits 12.2.15 - Authenticated Data Creation and Deletion via HTTP
CVSS 7.7
CVE-2026-61323
MEDIUM
Oracle Advanced Benefits - Improper Access Control
CVSS 6.5
CVE-2026-61322
HIGH
Oracle TeleSales 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-61314
HIGH
Oracle Edi Gateway < 12.2.15 - Improper Access Control
CVSS 7.2
CVE-2026-61312
HIGH
Oracle Product Hub 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP with Scope Change
CVSS 8.5
CVE-2026-61310
HIGH
Oracle Product Hub 12.2.3-12.2.15 - Authenticated Data Creation, Modification, and Access via HTTP
CVSS 8.1
CVE-2026-61309
HIGH
Oracle In-Memory Cost Mgmt for Discrete Industries 12.2.3-12.2.15 - Unauth Data Access via HTTP
CVSS 7.5
CVE-2026-61304
MEDIUM
Oracle Price Protection < 12.2.15 - Denial of Service
CVSS 6.3
CVE-2026-61301
HIGH
Oracle Process Manufacturing Financials 12.2.3-12.2.15 Authenticated Data Modification & Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-61299
HIGH
Oracle Process Manufacturing Logistics < 12.2.15 - Improper Access Control
CVSS 7.1
CVE-2026-61297
HIGH
Oracle Customers Online 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
Details
Vulnerabilities
6,224