PT-2023-9650 · Oracle · Oracle Database Server
Published
2023-12-07
·
Updated
2025-06-18
·
CVE-2024-21174
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Oracle Database Server versions 19.3 through 19.23
Oracle Database Server versions 21.3 through 21.14
Oracle Database Server version 23.4
Description
The issue is related to the Java VM component of Oracle Database Server, where an incorrect clearance or release of resources can be exploited. A low-privileged attacker with Create Session and Create Procedure privileges and network access via Oracle Net can compromise the Java VM. Successful attacks can result in a partial denial of service (partial DOS) of the Java VM.
Recommendations
For Oracle Database Server versions 19.3 through 19.23, update to a version that includes the fix for this issue.
For Oracle Database Server versions 21.3 through 21.14, update to a version that includes the fix for this issue.
For Oracle Database Server version 23.4, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting network access via Oracle Net to minimize the risk of exploitation.
Fix
DoS
Allocation of Resources Without Limits
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Database Server