Wednesday February 10, 2010 3:36 AM AEST
 
Latest Comments
"I too have been a labor voter for many years and will not be voting for them again. The ..."
by maxt | Feb 9, 2010 7:56 PM
 
"I’ve just had a user receive a rehashed version of this with an attached html file containing a ..."
by Owen Lutz | Feb 9, 2010 6:01 PM
 
"hi"
by manish kumar | Feb 9, 2010 4:27 PM
 
"Hey 'hey con-roy' ... from Google Australia's head of policy Iarla Flynn"We don't believe that ..."
by Keep it real | Feb 9, 2010 3:33 PM
 
"@penno Off-site storage is a good solution unless you have some decent backup software to ..."
by Charmgene | Feb 9, 2010 2:36 PM

Oracle to roll out huge patch update

  • Email a Friend
  • Print Page
Oracle to roll out huge patch update
By Phil Muncaster
Oct 19, 2009 9:17 AM
Tags: critical | fixes | oracle | patch | products | update
38 fixes across hundreds of products.

After Microsoft and Adobe both released their largest ever slew of patches last week, Oracle users will be bracing themselves for similar from their vendor, as the business software giant prepares a whopping 38 security vulnerability fixes this week.

The firm’s quarterly Critical Patch Update, set for 20 October, will contain fixes for problems across “hundreds of products”, according to a pre-release announcement.

The product which gets the most attention, as usual, is the Oracle Database, which has 16 new fixes, including six for vulnerabilities which could be remotely exploited without the need for authentication.

The Critical Patch Update will also feature eight fixes for the Oracle Applications Suite, including five which could be remotely exploited without the need for username and password.

The PeopleSoft and JD Edwards suite also features, with four new security fixes, while the update contains six fixes for the BEA Products Suite – the Oracle JRockit product receiving the maximum CVSS base score of 10.0.

“This Critical Patch Update contains 38 security vulnerability fixes across hundreds of Oracle products. Some of the vulnerabilities addressed in this Critical Patch Update affect multiple products,” read an Oracle statement.

“Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Patch Update fixes as soon as possible. Vulnerabilities fixed by Critical Patch Updates are scored using the standard CVSS 2.0 scoring.

The security update has been delayed for a week due to the Oracle OpenWorld conference last week.

Copyright © 2009 v3.co.uk

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Patch Management Whitepapers