First published: Tue Jul 16 2024(Updated: )
Vulnerability in the Oracle Database Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.23 and 21.3-21.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via DNS to compromise Oracle Database Portable Clusterware. While the vulnerability is in Oracle Database Portable Clusterware, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Database Portable Clusterware. CVSS 3.1 Base Score 5.8 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | >=19.3<=19.23>=21.3<=21.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21126 is classified as an easily exploitable vulnerability allowing unauthenticated attackers with network access to compromise Oracle Database Portable Clusterware.
To fix CVE-2024-21126, apply the latest security patches provided by Oracle for the affected versions of Oracle Database.
CVE-2024-21126 affects Oracle Database Server versions 19.3 to 19.23 and 21.3 to 21.14.
Yes, CVE-2024-21126 can be exploited remotely via DNS by an unauthenticated attacker.
If you are using Oracle Database Server versions 19.3 to 19.23 or 21.3 to 21.14, your system is vulnerable to CVE-2024-21126.