CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,568 vulnerabilities with CWE-287
CVE-2026-60924 HIGH
Oracle Public Sector Payroll 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60920 HIGH
Oracle Customer Care 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60908 HIGH
Oracle Installed Base 12.2.3-12.2.15 - Authenticated Data Access and Modification via Create Item Instance Component
CVSS 7.1
CVE-2026-60901 HIGH
Oracle Project Intelligence 12.2.3-12.2.15 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60898 HIGH
Oracle Warehouse Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-60897 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via Internal Operations Component
CVSS 8.8
CVE-2026-60890 HIGH
Oracle Payroll 12.2.3-12.2.15 - Authenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60872 HIGH
Oracle Order Management 12.2.3-12.2.15 - Authenticated Remote Code Execution via Product Diagnostic Tools
CVSS 8.8
CVE-2026-60863 HIGH
Oracle Advanced Pricing 12.2.3-12.2.15 - Authenticated Remote Takeover via Pricing Installation Component
CVSS 8.8
CVE-2026-60678 HIGH
Oracle General Ledger 12.2.3-12.2.15 - Authenticated Remote Code Execution via SOAP
CVSS 8.8
CVE-2026-60654 HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.8
CVE-2026-60615 HIGH
PeopleSoft Enterprise CS Campus Community 9.2.38 - Unauthenticated Data Access and Modification via HTTP
CVSS 8.2
CVE-2026-60583 HIGH
Oracle Transportation Management 6.5.3 - Authenticated Remote Takeover via Install Component
CVSS 8.8
CVE-2026-60579 HIGH
Oracle Enterprise Command Center Framework V16 - Unauth Data Modification & Info Disclosure via Physical Access
CVSS 8.0
CVE-2026-60578 HIGH
Oracle Enterprise Command Center Framework V16 - Authenticated Data Access and Modification via HTTP
CVSS 7.6
CVE-2026-60577 HIGH
Oracle Enterprise Command Center Framework V16 - Authenticated Data Access and Modification via HTTP
CVSS 7.1
CVE-2026-60568 CRITICAL
Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Runtime Tools Component
CVSS 9.9
CVE-2026-60558 HIGH
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
CVE-2026-60464 HIGH
Oracle WebCenter Content: Imaging 12.2.1.4.0 and 14.1.2.0.0 - Authenticated Remote Code Execution via Core Component
CVSS 8.8
CVE-2026-60434 MEDIUM
Oracle Transportation Management 6.5.3 - Authenticated Information Disclosure via HTTP
CVSS 4.3
CVE-2026-60423 HIGH
Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 - Authenticated Remote Takeover via LDAP
CVSS 8.8
CVE-2026-60416 HIGH
Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0 - Unauthenticated Remote Takeover via Authentication Engine
CVSS 8.1
CVE-2026-60357 LOW
Siebel CRM Integration 17.0-26.5 - Unauthenticated Data Manipulation via HTTP
CVSS 3.7
CVE-2026-60333 CRITICAL
Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0 - Authenticated Remote Takeover via Authentication Engine
CVSS 9.9
CVE-2026-60328 CRITICAL
Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0 - Unauthenticated Remote Takeover via Authentication Engine
CVSS 9.8
Details
Vulnerabilities 4,568
Exploit Likelihood High