When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,568 vulnerabilities with CWE-287
CVE-2026-60924
HIGH
Oracle Public Sector Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60920
HIGH
Oracle Customer Care 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60908
HIGH
Oracle Installed Base 12.2.3-12.2.15 - Authenticated Data Access and Modification via Create Item Instance Component
CVSS 7.1
CVE-2026-60901
HIGH
Oracle Project Intelligence 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60898
HIGH
Oracle Warehouse Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-60897
HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-60890
HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60872
HIGH
Oracle Order Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Product Diagnostic Tools
CVSS 8.8
CVE-2026-60863
HIGH
Oracle Advanced Pricing 12.2.3-12.2.15 - Authenticated Remote Takeover via Pricing Installation Component
CVSS 8.8
CVE-2026-60678
HIGH
Oracle General Ledger 12.2.3-12.2.15 - Authenticated Remote Code Execution via SOAP
CVSS 8.8
CVE-2026-60654
HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.8
CVE-2026-60615
HIGH
PeopleSoft Enterprise CS Campus Community 9.2.38 - Unauthenticated Data Access and Modification via HTTP
CVSS 8.2
CVE-2026-60583
HIGH
Oracle Transportation Management 6.5.3 - Authenticated Remote Takeover via Install Component
CVSS 8.8
CVE-2026-60579
HIGH
Oracle Enterprise Command Center Framework V16 - Unauth Data Modification & Info Disclosure via Physical Access
CVSS 8.0
CVE-2026-60578
HIGH
Oracle Enterprise Command Center Framework V16 - Authenticated Data Access and Modification via HTTP
CVSS 7.6
CVE-2026-60577
HIGH
Oracle Enterprise Command Center Framework V16 - Authenticated Data Access and Modification via HTTP
CVSS 7.1
CVE-2026-60568
CRITICAL
Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Runtime Tools Component
CVSS 9.9
CVE-2026-60558
HIGH
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
CVE-2026-60464
HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Core Component
CVSS 8.8
CVE-2026-60434
MEDIUM
Oracle Transportation Management 6.5.3 - Authenticated Information Disclosure via HTTP
CVSS 4.3
CVE-2026-60423
HIGH
Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 - Authenticated Remote Takeover via LDAP
CVSS 8.8
CVE-2026-60416
HIGH
Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0 - Unauthenticated Remote Takeover via Authentication Engine
CVSS 8.1
CVE-2026-60357
LOW
Siebel CRM Integration 17.0-26.5 - Unauthenticated Data Manipulation via HTTP
CVSS 3.7
CVE-2026-60333
CRITICAL
Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 - Authenticated Remote Takeover via Authentication Engine
CVSS 9.9
CVE-2026-60328
CRITICAL
Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0 - Unauthenticated Remote Takeover via Authentication Engine
CVSS 9.8
Details
Vulnerabilities
4,568
Exploit Likelihood
High