Java VM Vulnerability in Oracle Database Server
CVE-2026-21975
4.5MEDIUM
What is CVE-2026-21975?
A vulnerability exists in the Java VM component of Oracle Database Server that allows an authenticated user with network access to compromise the Java VM. This issue can lead to unauthorized actions, including causing persistent crashes or hangs, resulting in denial of service conditions. Successful exploitation typically requires human interaction from a third party, making this vulnerability particularly concerning for environments with inadequate user access controls.
Affected Version(s)
Oracle Database Server 19.3 <= 19.29
Oracle Database Server 21.3 <= 21.20