PT-2023-9650 · Oracle · Oracle Database Server
CVE-2024-21174
·
Publicado
2023-12-07
·
Atualizado
2025-06-18
CVSS v3.1
3.1
Baixa
| Vetor | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Oracle Database Server versions 19.3 through 19.23
Oracle Database Server versions 21.3 through 21.14
Oracle Database Server version 23.4
Description
The issue is related to the Java VM component of Oracle Database Server, where an incorrect clearance or release of resources can be exploited. A low-privileged attacker with Create Session and Create Procedure privileges and network access via Oracle Net can compromise the Java VM. Successful attacks can result in a partial denial of service (partial DOS) of the Java VM.
Recommendations
For Oracle Database Server versions 19.3 through 19.23, update to a version that includes the fix for this issue.
For Oracle Database Server versions 21.3 through 21.14, update to a version that includes the fix for this issue.
For Oracle Database Server version 23.4, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting network access via Oracle Net to minimize the risk of exploitation.
Correção
DoS
Allocation of Resources Without Limits
Improper Resource Release
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oracle Database Server