CVE-2024-21174: Low severity oracle database vulnerability
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.23, 21.3-21.14 and 23.4. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java VM. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21174?
CVE-2024-21174 is classified as a difficult to exploit vulnerability.
How do I fix CVE-2024-21174?
To fix CVE-2024-21174, ensure that you apply the latest security updates provided by Oracle for your affected version of the database.
Which versions of Oracle Database are affected by CVE-2024-21174?
CVE-2024-21174 affects Oracle Database versions 19.3 to 19.23, 21.3 to 21.14, and 23.4.
Who can exploit CVE-2024-21174?
CVE-2024-21174 can be exploited by low privileged attackers who have Create Session and Create Procedure privileges.
What component of Oracle Database is affected by CVE-2024-21174?
CVE-2024-21174 affects the Java VM component of the Oracle Database Server.