On CBS MoneyWatch: Which Credit Cards are Best?
BNET Business Network:
BNET
TechRepublic
ZDNet

October 12th, 2007

Oracle to patch 51 database, server flaws next Tuesday

Posted by Ryan Naraine @ 9:21 am

Categories: Botnets, Browsers, Data theft, Exploit code, Hackers, Passwords, Patch Watch, Pen testing, Privacy, Responsible disclosure, Spam and Phishing, Spyware and Adware, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: Oracle Enterprise Manager, Oracle Application Server, Database, Oracle Corp., Vulnerability, Server, Flaw, Security, Ryan Naraine

41 database, server patches comingDatabase and server giant Oracle plans to issue patches for a total of 51 security vulnerabilities next Tuesday (October 16).

According to an advance notice from Redwood City, the October Critical Patch Update will address flaws affecting Oracle Database, Oracle Application Server, Oracle E-Business Suite, Oracle Enterprise Manager, Oracle People Soft Enterprise and JD Edwards EnterpriseOne.

The company also said that its severity ratings system will now support CVSS v2, the latest revision of the common vulnerability scoring system.

This Oracle patch batch brings the total vulnerability count for 2007 to 183.

The skinny on next week’s updates:

Oracle Database is affected by 27 vulnerabilities. Five of these vulnerabilities may be remotely exploitable without authentication (may be exploited over a network without the need for a username and password). None of these fixes are applicable to Oracle Database client-only installations.

Oracle Application Server is affected by 11 vulnerabilities. Seven of these vulnerabilities may be remotely exploitable without authentication. No new fixes are applicable for client-only installations.

Oracle E-Business Suite and Applications is affected by 8 vulnerabilities. Only one the vulnerabilities is described as remotely exploitable without the need for authentication.

Oracle Enterprise Manager is affected by two vulnerabilities that may exploited over a network without the need for user/password credentials.

Oracle PeopleSoft Enterprise PeopleTools and JD Edwards EnterpriseOne affected by three vulnerabilities. None of these vulnerabilities may be exploited remotely without authentication.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 2 Talkback(s)
I am waiting
I am waiting to see what title Ryan Naraine gives the next Apple monster patch, and you know one will be released at some time in the very near future.

Or better, what title he gives the next L... (Read the rest)
Posted by: Qbt Posted on: 10/12/07 You are currently: a Guest | | Terms of Use
Proof positive of the ABM hit enhancer on ZDNet  Confused by religion | 10/12/07
I am waiting  Qbt | 10/12/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline