Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Oracle Database Sharding. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Database Sharding. CVSS 3.1 Base Score 2.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:L).
References
Link | Resource |
---|---|
https://www.oracle.com/security-alerts/cpuapr2024.html | Vendor Advisory |
https://www.oracle.com/security-alerts/cpuapr2024.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
03 Dec 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-404 |
27 Nov 2024, 16:37
Type | Values Removed | Values Added |
---|---|---|
First Time |
Oracle database Server
Oracle |
|
CWE | NVD-CWE-noinfo | |
References | () https://www.oracle.com/security-alerts/cpuapr2024.html - Vendor Advisory | |
CPE | cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*:* |
21 Nov 2024, 08:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.oracle.com/security-alerts/cpuapr2024.html - |
17 Apr 2024, 12:48
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
16 Apr 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-16 22:15
Updated : 2024-12-03 17:15
NVD link : CVE-2024-20995
Mitre link : CVE-2024-20995
CVE.ORG link : CVE-2024-20995
JSON object : View
Products Affected
oracle
- database_server
CWE