« Volver al listado

CVE-2024-21066

Estado: AnalizadaMedia (4.2)—

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS executes to compromise RDBMS. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all RDBMS accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-21066",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-21066",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-04-18T16:23:24.806626Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert_us@oracle.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.2,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.6
      }
    ]
  },
  "affected": [
    {
      "source": "secalert_us@oracle.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:oracle:database_-_rdbms:19.3-19.22:*:*:*:*:*:*:*",
            "cpe:2.3:a:oracle:database_-_rdbms:21.3-21.13:*:*:*:*:*:*:*"
          ],
          "vendor": "Oracle Corporation",
          "product": "Database - Enterprise Edition",
          "versions": [
            {
              "status": "affected",
              "version": "19.3",
              "versionType": "custom",
              "lessThanOrEqual": "19.22"
            },
            {
              "status": "affected",
              "version": "21.3",
              "versionType": "custom",
              "lessThanOrEqual": "21.13"
            }
          ]
        }
      ]
    }
  ],
  "published": "2024-04-16T22:15:24.957",
  "references": [
    {
      "url": "https://www.oracle.com/security-alerts/cpuapr2024.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert_us@oracle.com"
    },
    {
      "url": "https://www.oracle.com/security-alerts/cpuapr2024.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 19.3-19.22 and  21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS executes to compromise RDBMS.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all RDBMS accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N)."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad en el componente RDBMS de Oracle Database Server. Las versiones compatibles que se ven afectadas son 19.3-19.22 y 21.3-21.13. Una vulnerabilidad fácilmente explotable permite que un atacante con altos privilegios tenga permisos de usuario autenticado e inicie sesión en la infraestructura donde se ejecuta RDBMS para comprometer RDBMS. Los ataques exitosos requieren la interacción humana de una persona distinta del atacante. Los ataques exitosos a esta vulnerabilidad pueden resultar en un acceso no autorizado a datos críticos o un acceso completo a todos los datos accesibles del RDBMS. CVSS 3.1 Puntaje base 4.2 (Impactos en la confidencialidad). Vector CVSS: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N). "
    }
  ],
  "lastModified": "2026-06-17T07:08:28.067",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "670AED82-4D63-4464-B3C6-AE4BA189FCFC",
              "versionEndIncluding": "19.22",
              "versionStartIncluding": "19.3"
            },
            {
              "criteria": "cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75461A23-1D7B-4C84-A216-364137729397",
              "versionEndIncluding": "21.13",
              "versionStartIncluding": "21.3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert_us@oracle.com"
}