PT-2024-4992 · Oracle · Oracle Database Server+1

Published

2024-07-16

·

Updated

2025-06-18

·

CVE-2024-21126

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Oracle Database Server versions 19.3 through 19.23 Oracle Database Server versions 21.3 through 21.14
Description: The issue is related to insufficient input validation in the Oracle Database Portable Clusterware component, allowing an unauthenticated attacker with network access via DNS to compromise Oracle Database Portable Clusterware. Successful attacks can result in a partial denial of service (partial DOS) of Oracle Database Portable Clusterware, potentially impacting additional products.
Recommendations: For versions 19.3 through 19.23, update to a version outside of this range to resolve the issue. For versions 21.3 through 21.14, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the Oracle Database Portable Clusterware component to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-05516
CVE-2024-21126

Affected Products

Oracle Database Portable Clusterware
Oracle Database Server