Cyber Resilience

CVE-2024-21093

Oracle Java Virtual Machine 19.3 – 19.22

Published
16 April 2024
Modified
06 December 2024
Patch / advisory
CVSS Score v3.1 5.3
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0043 36th percentile
Risk Priority 42 floored blend · peak EPSS

Summary

CVE-2024-21093 is a medium-severity an unspecified weakness vulnerability in Oracle Java Virtual Machine. Its CVSS base score is 5.3 (Medium).

Operationally, ranked at the 36th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to…

more

compromise Java VM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java VM accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).

CWE(s)

Related Threats

CVEs Like This One

CVE-2026-21975Same product: Oracle Java Virtual Machine
CVE-2025-50069Same product: Oracle Java Virtual Machine
CVE-2025-21553Same product: Oracle Java Virtual Machine
CVE-2025-61881Same product: Oracle Java Virtual Machine
CVE-2026-35229Same product: Oracle Java Virtual Machine
CVE-2025-30736Same product: Oracle Java Virtual Machine
CVE-2026-46781Same vendor: Oracle
CVE-2026-60799Same vendor: Oracle
CVE-2024-21133Same vendor: Oracle
CVE-2026-21959Same vendor: Oracle

Affected Assets

oracle
java virtual machine
19.3 — 19.22 · 21.3 — 21.13

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References