PT-2023-9650 · Oracle · Oracle Database Server

CVE-2024-21174

·

Publicado

2023-12-07

·

Atualizado

2025-06-18

CVSS v3.1

3.1

Baixa

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Oracle Database Server versions 19.3 through 19.23 Oracle Database Server versions 21.3 through 21.14 Oracle Database Server version 23.4
Description The issue is related to the Java VM component of Oracle Database Server, where an incorrect clearance or release of resources can be exploited. A low-privileged attacker with Create Session and Create Procedure privileges and network access via Oracle Net can compromise the Java VM. Successful attacks can result in a partial denial of service (partial DOS) of the Java VM.
Recommendations For Oracle Database Server versions 19.3 through 19.23, update to a version that includes the fix for this issue. For Oracle Database Server versions 21.3 through 21.14, update to a version that includes the fix for this issue. For Oracle Database Server version 23.4, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting network access via Oracle Net to minimize the risk of exploitation.

Correção

DoS

Allocation of Resources Without Limits

Improper Resource Release

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-09197
CVE-2024-21174

Produtos afetados

Oracle Database Server