CVE-2024-21126: Medium severity oracle database vulnerability
Vulnerability in the Oracle Database Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.23 and 21.3-21.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via DNS to compromise Oracle Database Portable Clusterware. While the vulnerability is in Oracle Database Portable Clusterware, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Database Portable Clusterware. CVSS 3.1 Base Score 5.8 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21126?
CVE-2024-21126 is classified as an easily exploitable vulnerability allowing unauthenticated attackers with network access to compromise Oracle Database Portable Clusterware.
How do I fix CVE-2024-21126?
To fix CVE-2024-21126, apply the latest security patches provided by Oracle for the affected versions of Oracle Database.
Which versions are affected by CVE-2024-21126?
CVE-2024-21126 affects Oracle Database Server versions 19.3 to 19.23 and 21.3 to 21.14.
Can the CVE-2024-21126 vulnerability be exploited remotely?
Yes, CVE-2024-21126 can be exploited remotely via DNS by an unauthenticated attacker.
Is my Oracle Database vulnerable to CVE-2024-21126?
If you are using Oracle Database Server versions 19.3 to 19.23 or 21.3 to 21.14, your system is vulnerable to CVE-2024-21126.