PT-2024-4992 · Oracle · Oracle Database Server+1
Published
2024-07-16
·
Updated
2025-06-18
·
CVE-2024-21126
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Oracle Database Server versions 19.3 through 19.23
Oracle Database Server versions 21.3 through 21.14
Description:
The issue is related to insufficient input validation in the Oracle Database Portable Clusterware component, allowing an unauthenticated attacker with network access via DNS to compromise Oracle Database Portable Clusterware. Successful attacks can result in a partial denial of service (partial DOS) of Oracle Database Portable Clusterware, potentially impacting additional products.
Recommendations:
For versions 19.3 through 19.23, update to a version outside of this range to resolve the issue.
For versions 21.3 through 21.14, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting access to the Oracle Database Portable Clusterware component to minimize the risk of exploitation.
Fix
DoS
Resource Exhaustion
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Database Portable Clusterware
Oracle Database Server