Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with logon to the infrastructure where Oracle Database Core executes to compromise Oracle Database Core. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Database Core accessible data. CVSS 3.1 Base Score 2.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).
History

Wed, 18 Jun 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle
Oracle database Server
CPEs cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database Server

Tue, 05 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published: 2024-07-16T22:39:45.449Z

Updated: 2024-11-05T16:36:46.928Z

Reserved: 2023-12-07T22:28:10.681Z

Link: CVE-2024-21123

cve-icon Vulnrichment

Updated: 2024-08-01T22:13:42.680Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-16T23:15:11.810

Modified: 2025-06-18T20:22:51.080

Link: CVE-2024-21123

cve-icon Redhat

No data.