PT-2023-9650 · Oracle · Oracle Database Server

Published

2023-12-07

·

Updated

2025-06-18

·

CVE-2024-21174

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Oracle Database Server versions 19.3 through 19.23 Oracle Database Server versions 21.3 through 21.14 Oracle Database Server version 23.4
Description The issue is related to the Java VM component of Oracle Database Server, where an incorrect clearance or release of resources can be exploited. A low-privileged attacker with Create Session and Create Procedure privileges and network access via Oracle Net can compromise the Java VM. Successful attacks can result in a partial denial of service (partial DOS) of the Java VM.
Recommendations For Oracle Database Server versions 19.3 through 19.23, update to a version that includes the fix for this issue. For Oracle Database Server versions 21.3 through 21.14, update to a version that includes the fix for this issue. For Oracle Database Server version 23.4, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting network access via Oracle Net to minimize the risk of exploitation.

Fix

DoS

Allocation of Resources Without Limits

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2024-09197
CVE-2024-21174

Affected Products

Oracle Database Server