Description
Vulnerability in the Oracle Database RDBMS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having Execute on SYS.XS_DIAG privilege with network access via Oracle Net to compromise Oracle Database RDBMS Security. Successful attacks of this vulnerability can result in takeover of Oracle Database RDBMS Security. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-18898 | Vulnerability in the Oracle Database RDBMS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having Execute on SYS.XS_DIAG privilege with network access via Oracle Net to compromise Oracle Database RDBMS Security. Successful attacks of this vulnerability can result in takeover of Oracle Database RDBMS Security. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). |
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2024.html |
|
History
No history.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2024-08-01T22:13:42.829Z
Reserved: 2023-12-07T22:28:10.688Z
Link: CVE-2024-21184
Updated: 2024-08-01T22:13:42.829Z
Status : Modified
Published: 2024-07-16T23:15:23.077
Modified: 2024-11-21T08:53:56.900
Link: CVE-2024-21184
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD