CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

6,227 vulnerabilities with CWE-284
CVE-2026-61207 CRITICAL
PeopleSoft Enterprise SCM eProcurement 9.2 - Unauthenticated Unauthorized Data Access and Modification via HTTP
CVSS 9.3
CVE-2026-61205 HIGH
PeopleSoft Enterprise SCM Purchasing 9.2 - Unauthenticated Data Creation/Modification/Read via HTTP
CVSS 8.2
CVE-2026-61204 CRITICAL
PeopleSoft Enterprise FIN Program Mgmt 9.2 Auth RCE via Primavera Integration
CVSS 9.0
CVE-2026-61203 CRITICAL
Oracle Corporation PeopleSoft Enterprise Fin Expenses - Denial of Service
CVSS 9.4
CVE-2026-61202 HIGH
Oracle Solaris 11.3-11.4 - Authenticated Critical Data Access and Modification via Utility Component
CVSS 7.5
CVE-2026-61201 CRITICAL
PeopleSoft Enterprise CRM Common Objects 9.2.23 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.0
CVE-2026-61200 MEDIUM
Oracle Labor Distribution < 12.2.15 - Improper Access Control
CVSS 5.4
CVE-2026-61197 CRITICAL
Oracle Identity Manager 12.2.1.4.0/14.1.2.1.0 - Unauthenticated Critical Data Creation/Modification/Access via Legacy UI
CVSS 9.1
CVE-2026-61191 MEDIUM
Oracle Agile Engineering Data Management - Denial of Service
CVSS 4.4
CVE-2026-61190 MEDIUM
Oracle Agile Engineering Data Mgmt 6.2.1 - Authenticated Data Modification & Unauthorized Access via Install
CVSS 6.4
CVE-2026-61189 MEDIUM
Oracle Agile Engineering Data Management 6.2.1 - Authenticated Unauthorized Critical Data Access via Install Component
CVSS 6.5
CVE-2026-61186 CRITICAL
Oracle Agile Engineering Data Management - Denial of Service
CVSS 9.4
CVE-2026-61184 CRITICAL
Oracle Agile PLM for Process 6.2.4 - Unauthenticated Critical Data Access/Modification via HTTP
CVSS 9.1
CVE-2026-61181 HIGH
Oracle Agile PLM for Process 6.2.4: Authenticated Data Access/Modification via Product Quality Mgmt
CVSS 7.6
CVE-2026-61179 HIGH
Oracle Agile PLM for Process 6.2.4: Authenticated Remote Takeover via PQM Component
CVSS 8.8
CVE-2026-61176 MEDIUM
Oracle Product Lifecycle Analytics - Denial of Service
CVSS 6.7
CVE-2026-61174 CRITICAL
Oracle Product Lifecycle Analytics 3.6.1 - Unauthenticated Critical Data Access/Modification via Local Logon
CVSS 9.0
CVE-2026-61173 HIGH
Oracle Agile PLM 9.3.6 - Unauthenticated Data Modification and Unauthorized Data Access via HTTP
CVSS 7.4
CVE-2026-61172 HIGH
Oracle Agile PLM 9.3.6 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
CVE-2026-61171 CRITICAL
Oracle Agile PLM 9.3.6 - Unauthenticated Critical Data Access and Modification via HTTP
CVSS 9.1
CVE-2026-61170 HIGH
Oracle Agile PLM 9.3.6 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
CVE-2026-61169 MEDIUM
Oracle Agile PLM 9.3.6 - Authenticated Unauthorized Critical Data Access via Security Component
CVSS 6.5
CVE-2026-61168 HIGH
Oracle Agile PLM 9.3.6 - Authenticated Remote Code Execution via Security Component
CVSS 8.8
CVE-2026-61167 CRITICAL
Oracle Agile PLM 9.3.6 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-61166 HIGH
Oracle Agile PLM 9.3.6 - Authenticated Remote Code Execution via User and User Group Component
CVSS 8.8
Details
Vulnerabilities 6,227