CVE-2024-21093

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 16, 2024
Updated: Apr 17, 2024

Summary

CVE-2024-21093 is a vulnerability affecting the Java VM component in Oracle Database Server. Versions 19.3 to 19.22 and 21.3 to 21.13 are reported to be susceptible. This issue enables a low-privileged attacker, with Create Session and Create Procedure privileges and network access via Oracle Net, to compromise the Java VM. The consequence of a successful exploit can lead to unauthorized access to critical data or complete access to all Java VM accessible data, with a CVSS 3.1 Base Score of 5.3 for Confidentiality impacts. The attack vector is network-accessible (AV:N) with high attack complexity (AC:H), requiring low privileges (PR:L), and having no user interaction (UI:N) or temporary effects (S:U).

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share