Java VM Vulnerability Affects Oracle Database Server
CVE-2024-21093
5.3MEDIUM
Summary
A vulnerability exists in the Java VM component of Oracle Database Server that could allow a low-privileged attacker with limited privileges, such as Create Session and Create Procedure, to exploit flaws with network access through Oracle Net. If successfully exploited, this vulnerability may lead to unauthorized access to confidential data or provide complete access to all information accessible via the Java VM. Users of affected versions should ensure their systems are updated to mitigate potential security risks.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published