Unauthenticated Remote Code Execution in Oracle Database Server's Clusterware
CVE-2024-21126

5.8MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 July 2024

Summary

An unauthenticated remote code execution vulnerability exists in the Oracle Database Portable Clusterware component of Oracle Database Server, specifically affecting versions 19.3 through 19.23 and 21.3 through 21.14. An attacker with network access via DNS could exploit this vulnerability to compromise the Clusterware, potentially leading to unauthorized changes and partial denial of service conditions. Although the vulnerability resides within the Clusterware, the ramifications may extend beyond it, impacting additional Oracle products.

Affected Version(s)

Database - Enterprise Edition 19.3 <= 19.23

Database - Enterprise Edition 21.3 <= 21.14

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.