Unauthenticated Remote Code Execution in Oracle Database Server's Clusterware
CVE-2024-21126
5.8MEDIUM
What is CVE-2024-21126?
An unauthenticated remote code execution vulnerability exists in the Oracle Database Portable Clusterware component of Oracle Database Server, specifically affecting versions 19.3 through 19.23 and 21.3 through 21.14. An attacker with network access via DNS could exploit this vulnerability to compromise the Clusterware, potentially leading to unauthorized changes and partial denial of service conditions. Although the vulnerability resides within the Clusterware, the ramifications may extend beyond it, impacting additional Oracle products.
Affected Version(s)
Database - Enterprise Edition 19.3 <= 19.23
Database - Enterprise Edition 21.3 <= 21.14