• Home
  • Et Cetera

Infosecurity.US

ORACLE Slates 38 Patches… Alert The Media

By Marc Handelman on October 19th, 2009

Oracle

News, from last week, of Oracle Corporation’s (NasdaqGS: ORCL) slated critical security updates and bug fix patches for the Redwood Shores, CA based software giant’s database server and application server products. The list affected are a smorgasboard of the company’s offerings: Oracle Database 11g, version 11.1.0.7, Oracle Database 10g Release 2, versions 10.2.0.3, 10.2.0.4, Oracle Database 10g, version 10.1.0.5, Oracle Database 9i Release 2, versions 9.2.0.8, 9.2.0.8DV, Oracle Application Server 10g Release 3 (10.1.3), versions 10.1.3.4.0, 10.1.3.5.0, Oracle Application Server 10g Release 2 (10.1.2), version 10.1.2.3.0, Oracle Business Intelligence Enterprise Edition, versions 10.1.3.4.0, 10.1.3.4.1, Oracle E-Business Suite Release 12, versions 12.0.6 and 12.1, Oracle E-Business Suite Release 11i, version 11.5.10.2, AutoVue, version 19.3, Agile Engineering Data Management (EDM), version 6.1, PeopleSoft PeopleTools & Enterprise Portal, version 8.49, PeopleSoft Enterprise HCM (TAM), versions 8.9 and 9.0, JD Edward Tools, version 8.98, Oracle WebLogic Server 10.0 through MP1 and 10.3, Oracle WebLogic Server 9.0 GA, 9.1 GA and 9.2 through 9.2 MP3, Oracle WebLogic Server 8.1 through 8.1 SP5, Oracle WebLogic Server 7.0 through 7.0 SP6, Oracle WebLogic Portal, versions 8.1 through 8.1 SP6, 9.2 through 9.2 MP3, 10.0 through 10.0MP1, 10.2 through 10.2MP1 and 10.3 through 10.3.1, Oracle JRockit R27.6.4 and earlier (JDK/JRE 6, 5, 1.4.2), Oracle Communications Order and Service Management, versions 2.8.0, 6.2.0, 6.3.0 and 6.3.1. More information, including release notes, and a short snippet form the news post, appears after the jump.

Oracle Critical Patch Update Pre-Release Announcement – October 2009

Description

This Critical Patch Update Pre-Release Announcement provides advance information about the Oracle Critical Patch Update for October 2009, which will be released on Tuesday, October 20, 2009.  While this Pre-Release Announcement is as accurate as possible at the time of publication, the information it contains may change before publication of the Critical Patch Update Advisory.

A Critical Patch Update is a collection of patches for multiple security vulnerabilities. This Critical Patch Update contains 38 security vulnerability fixes across hundreds of Oracle products.  Some of the vulnerabilities addressed in this Critical Patch Update affect multiple products.  Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Patch Update fixes as soon as possible.

Vulnerabilities fixed by Critical Patch Updates are scored using the standard CVSS 2.0 scoring (see Oracle’s Use of CVSS Scoring). The highest CVSS 2.0 base score for vulnerabilities in this Critical Patch Update is 10.0 for vulnerabilities affecting Oracle Core RDBMS, Oracle JRockit and Oracle Network Authentication.

Supported Products Affected

Security vulnerabilities addressed by this Critical Patch Update affect the following products:

• Oracle Database 11g, version 11.1.0.7
• Oracle Database 10g Release 2, versions 10.2.0.3, 10.2.0.4
• Oracle Database 10g, version 10.1.0.5
• Oracle Database 9i Release 2, versions 9.2.0.8, 9.2.0.8DV
• Oracle Application Server 10g Release 3 (10.1.3), versions 10.1.3.4.0, 10.1.3.5.0
• Oracle Application Server 10g Release 2 (10.1.2), version 10.1.2.3.0
• Oracle Business Intelligence Enterprise Edition, versions 10.1.3.4.0, 10.1.3.4.1
• Oracle E-Business Suite Release 12, versions 12.0.6 and 12.1
• Oracle E-Business Suite Release 11i, version 11.5.10.2
• AutoVue, version 19.3
• Agile Engineering Data Management (EDM), version 6.1
• PeopleSoft PeopleTools & Enterprise Portal, version 8.49
• PeopleSoft Enterprise HCM (TAM), versions 8.9 and 9.0
• JD Edward Tools, version 8.98
• Oracle WebLogic Server 10.0 through MP1 and 10.3
• Oracle WebLogic Server 9.0 GA, 9.1 GA and 9.2 through 9.2 MP3
• Oracle WebLogic Server 8.1 through 8.1 SP5
• Oracle WebLogic Server 7.0 through 7.0 SP6
• Oracle WebLogic Portal, versions 8.1 through 8.1 SP6, 9.2 through 9.2 MP3, 10.0 through 10.0MP1, 10.2 through 10.2MP1 and 10.3 through 10.3.1
• Oracle JRockit R27.6.4 and earlier (JDK/JRE 6, 5, 1.4.2)
• Oracle Communications Order and Service Management, versions 2.8.0, 6.2.0, 6.3.0 and 6.3.1

Executive Summaries

Oracle Database Executive Summary

This Critical Patch Update contains 16 new security vulnerability fixes for the Oracle Database. 6 of these vulnerabilities may be remotely exploited without authentication, i.e., may be exploited over a network without the need for a username and password.  1 of these fixes is applicable to Oracle Database client-only installations, i.e., installations that do not have the Oracle Database installed.

The highest CVSS base score of vulnerabilities affecting Oracle Database products is 10.0 for Windows versions of the product and 7.5 for all other platforms.

The Oracle Database components affected by vulnerabilities that are fixed in this Critical Patch Update are:

  • Advanced Queuing
  • Application Express
  • Authentication
  • CORE RDBMS
  • Data Mining
  • Net Foundation Layer
  • Network Authentication
  • Oracle Spatial
  • Oracle Text
  • PL/SQL
  • RDBMS Data Pump
  • RDBMS Security
  • Workspace Manager

Oracle Application Server Executive Summary

This Critical Patch Update contains 3 new security fixes for the Oracle Application Server. 2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password. None of these fixes are applicable to client-only installations, i.e., installations that do not have an Oracle Application Server installed.

Oracle Application Server products that are bundled with the Oracle Database are affected by Oracle Database vulnerabilities fixed in this CPU.

The highest CVSS base score of vulnerabilities affecting Oracle Application Server products is 4.3.

The Oracle Application Server components affected by vulnerabilities that are fixed in this Critical Patch Update are:

  • Oracle Business Intelligence Enterprise Edition
  • Oracle Portal

Oracle E-Business Suite and Applications Executive Summary

This Critical Patch Update contains 8 new security fixes for the Oracle Applications Suite. 5 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password. None of these fixes is applicable to client-only installations, i.e., installations that do not have an Oracle Applications installed.

Oracle E-Business Suite products use Oracle Database and Oracle Application Server products which have vulnerabilities fixed in this CPU. These vulnerabilities should be patched (the documentation released with the Critical Patch Update will provide details).

The highest CVSS base score of vulnerabilities affecting E-Business Suite products is 5.5.

The Oracle E-Business Suite components affected by vulnerabilities that are fixed in this Critical Patch Update are:

  • Agile Engineering Data Management (EDM)
  • AutoVue
  • Oracle Advanced Benefits
  • Oracle Application Object Library
  • Oracle Applications Framework
  • Oracle Applications Technology Stack

Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne Executive Summary

This Critical Patch Update contains 4 new security fixes for the PeopleSoft and JD Edwards Suite. None of these vulnerabilities may be remotely exploitable without authentication, i.e., none may be exploited over a network without the need for a username and password.

The highest CVSS base score of vulnerabilities affecting Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne products is 4.1.

The Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne components affected by vulnerabilities that are fixed in this Critical Patch Update are:

  • JD Edwards Tools
  • PeopleSoft Enterprise HCM (TAM)
  • PeopleSoft PeopleTools & Enterprise Portal

Oracle BEA Products Executive Summary

This Critical Patch Update contains 6 new security fixes for the BEA Products Suite. All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password.

The highest CVSS base score of vulnerabilities affecting Oracle BEA Products is 10.0 in Oracle JRockit.

The Oracle BEA Products affected by vulnerabilities that are fixed in this Critical Patch Update are:

  • Oracle JRockit
  • Oracle WebLogic Portal
  • Oracle WebLogic Server

Oracle Industry Applications Products Executive Summary

This Critical Patch Update contains 1 new security fix for the Oracle Industry Applications Products Suite. This vulnerability is not remotely exploitable without authentication, i.e., may not be exploited over a network without the need for a username and password.

The CVSS base score of the vulnerability affecting Oracle Industry Applications Products is 4.9.

Oracle Industry Applications product affected by the vulnerability that is fixed in this Critical Patch Update is:

  • Oracle Communications Order and Service Management

From PCWorld’s Robert McMillan (of the IDG News Service): “38 Oracle Security Patches Coming Next Week“
“After a record-setting week of Microsoft and Adobe security patches, Oracle is gearing up for a major update of its own next week. Next Tuesday, the database vendor will release its quarterly Critical Patch Update, which “contains 38 security vulnerability fixes across hundreds of Oracle products,” according to an advance notification posted to Oracle’s Web site. As usual, Oracle’s most-patched product next week will be its flagship database, which will get 16 bug fixes. Six of these flaws may be exploitable over a network without any type of authentication, Oracle said. Also in the mix are eight fixes for the company’s E-Business Suite, three for Oracle Application Server and one for the Industry Applications Products Suite. Patches are also planned for Oracle’s BEA, PeopleSoft and JD Edwards software…”

Categories: Infosecurity, Oracle CPU, Oracle Corporation, Oracle Database Security, Oracle Enterprise Manager, Oracle Security, Software Patches
Tags: BEA PeopleSoft, J. D. Edwards, JRockit, Oracle Application Server, Oracle Corporation, Oracle Databases, Oracle E-Business Suite, Software Patches, Software Patching, WebLogic

Related Headlines

    Related posts:

    1. Oracle January Critical Patch Update Imminent
    2. US-CERT: Oracle Critical Patch Update Notification
    3. Oracle Patches Critical WebLogic Flaw
    4. US-CERT: Oracle Releases July Critical Patch Update
    5. Oracle Enterprise Manager DB Grid Control Security Update

Comments are closed.

« Lisa Benson: Hillary On The Menu Dilbert: Retirement Account »
  • Latest
  • Random
  • Bookmarks
  • Archives
  • Steve Benson: Persian Lights…
  • New, Pernicious BotNet Emerges
  • VMWare Announces ESX Console Security Update
  • Nick Anderson: Egg
  • Doppelgänger Infinitus
  • Robert Ariall: Iran For Cover
  • Data Leakage Wednesdays: Old Printer Vector
  • XKCD: Exoplanets
  • Apple Releases Magic Footpad, Raises Ante On Bipedal Computer Controls
  • Science Tuesday: Asteroidal Discoveries Mapped, 01980 – 02010
  • XKCD: Newton and Leibniz
  • Update – Apache Foundation Announces TOMCAT Vulnerability
  • OWASP – Italy Announces Day VI Secure Software Initiatives, Call For Papers
  • Dinosaur Comics: Plans
  • John Leo: Vader’s Tai Chi
  • MBTA Vulnerability Released To Web. By The MBTA…
  • Beckstrom Moves Into ICANN Presidency, Can He Clean It Up?
  • Conficker Ariseth – Rears Ugly Head, Drops Files…
  • Disgruntled Employee Hacks Automobile Dealer Remote Repossession System
  • SAP MaxDB Vulnerability
  • Apple
  • BSD
  • Closson
  • Darknet
  • Debian
  • Finnigan
  • ha.ckers
  • Hoff
  • Insecure
  • Krebs
  • Layer8
  • MSRC
  • Network Security Blog
  • NSA SEL
  • openSUSE
  • RedHat
  • SANS
  • Schneier
  • Security Eunoia
  • Securosis
  • Shimel
  • September 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
Subscribe

Featured Blog - Blogs.com SANS Security Reading Room KnotOriginal: fine art to hang on your body and walls Member - Security Bloggers Network

Dilbert

KnotOriginal

Featured Video

QOTD

RSS Security Bloggers Network

  • Two Wheel EV Recumbant: Zerotracer 2010/09/02 Davi Ottenheimer
  • Ben Franklin’s Endpoint Security Advice 2010/09/02 Jeff Hughes
  • Configuring Conditional SSH Connections 2010/09/02 Xavier
  • Truecrypt and USB drives 2010/09/02 always peace
  • LogChat Podcast 1: Anton Chuvakin and Andrew Hay Talk Logs 2010/09/02 Andrew Hay
  • Safe Web Surfing Rule # 1: READ the URL 2010/09/02 Tom Kelchner
  • Heartland Set To Pay Discover $5M For 2008 Data Breach 2010/09/02 spinman
  • User’s Opinions on Malware Infections 2010/09/02 spinman
  • Acunetix Web Vulnerability Scanner 7 Released 2010/09/02 spinman
  • LogChat Podcast 1: Anton Chuvakin and Andrew Hay Talk Logs 2010/09/02 Anton Chuvakin

RSS Cryptography

  • Monitor: Schrodinger's cat and mouse 2010/09/02
  • How to configure a Junos security device 2010/09/02
  • Net Effect: Hay-what? 2010/09/02
  • The Art of Proof 2010/09/02
  • Quantum crypto cracked, researchers say 2010/09/01

RSS SANS ISC

  • Microsoft EMETv2 released, (Thu, Sep 2nd) 2010/09/02
  • SDF, please!, (Thu, Sep 2nd) 2010/09/02
  • Month of Undisclosed 0-day Bugs, (Wed, Sep 1st) 2010/09/01
  • Microsoft issues updates to sysinternals ProcDump and Process Monitor: http://blogs.technet.com/b/sysinternals/archive/2010/08/30/updates-procdump-process-monitor-and-a-new-mark-s-blog-post.aspx, (Wed, Sep 1st) 2010/09/01
  • VMWARE releases 2 security advisories for ESX Service Console: http://lists.vmware.com/pipermail/security-announce/2010/000103.html and http://lists.vmware.com/pipermail/security-announce/2010/000104.html, (Wed, Sep 1st) 2010/09/01

RSS Oracle

  • Going to Oracle OpenWorld 2010? 2010/09/02
  • Automatic Time Zone support in Application Express 4.0 2010/09/02
  • EBS, Collaborate, Security, BPEL, OWB, Blog of Note, Hyperion, EPM, Burnout, WiFi 2010/09/02
  • Details of Tuxedo sessions at OOW 2010/09/02
  • JavaOne Preview on TechCast Live! (Tues., Sept. 7, 10am PT) 2010/09/02
  • links for 2010-09-02 2010/09/02
  • Join us for a Bersin & Associates Webcast - "Evolution of ERPs: Driving Business Value through Integrated Talent Management" 2010/09/02

RSS MySQL

  • Join MySQL at OSCON 2010/07/02
  • TechCast Live: Jono Bacon and Luke Kowalski on MySQL Community 2010/05/21
  • What's New in the MySQL Enterprise Spring 2010 Release? - Interview with Mark Matthews and Andy Bang 2010/05/17
  • Introduction to MySQL 5.5 2010/04/13
  • Why Should I Check Out a MySQL-Based Column Database ? 2010/02/12
  • A deep look at MySQL 5.5 partitioning enhancements 2009/12/24
  • Sun "Tech Days" Conference World Tour Kicks Off in Brazil 2009/12/07

RSS Linux

  • A Guide to Today's Top 10 Linux Distributions - NetworkWorld.com 2010/09/02
  • Embedded Linux Conference videos available - LWN.net 2010/09/02
  • Net Applications' iOS vs Linux Report Confuses Me - Muktware (blog) 2010/09/02
  • Cloudlinux Named Editor's Choice By Web Host Magazine & Buyer's Guide - PR Urgent 2010/09/02
  • Samsung's 3D TV remote let's you take the screen with you - Geek.com 2010/09/02

RSS MAC OSX

  • Samsung Reveals Half-Pint iPad, The Galaxy Tab 2010/09/02 Eli Milchman
  • Daily Deals: New nano, touch and Apple TV 2010/09/02 Ed Sutherland
  • iPhone 4 Coffee Table Gets You Better Reception Than iPod Table? 2010/09/02 Nicole Martinelli
  • Walkman Outsells iPods in Japan, Can Wristwatch Nano Change That? 2010/09/02 Nicole Martinelli
  • Amazon: Buy – Don’t Rent – 99-Cent Fox, ABC TV Episodes 2010/09/02 Ed Sutherland
  • Analyst: New Apple TV Rival for Cable’s Video-on-Demand 2010/09/02 Ed Sutherland
  • iTunes Ping And Facebook: What’s Going On? 2010/09/02 Giles Turnbull

RSS Microsoft

  • Update on Security Advisory 2269637 2010/08/31 MSRCTEAM
  • Microsoft Security Advisory 2269637 Released 2010/08/22 MSRCTEAM
  • August 2010 Webcast and QA 2010/08/12 MSRCTEAM
  • Update on the publicly disclosed Win32k.sys EoP Vulnerability 2010/08/10 MSRCTEAM
  • August 2010 Security Bulletin Release 2010/08/10 MSRCTEAM
  • August 2010 Bulletin Release Advance Notification 2010/08/05 MSRCTEAM
  • August 2010 Out-of-Band Security Release Webcast Q&A 2010/08/03 MSRCTEAM

RSS Network

  • How to get started with a blade system 2010/09/02
  • Opsview Community Edition review 2010/09/02
  • Cacti review 2010/09/02
  • Brocade adds 100G Ethernet to switch and router line 2010/09/02
  • Is Cisco making a play for Skype? 2010/08/31
  • Skype launches Skype Connect enterprise voice calling 2010/08/31
  • Sonos ZonePlayer S5 review 2010/08/25

Daily Posts

September 2010
S M T W T F S
« Aug    
 1234
567891011
12131415161718
19202122232425
2627282930  
Creative Commons License
The Infosecurity.US Blog is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.

Find the best blogs at Blogs.com.

Creative Commons Attribution-Share Alike 3.0 U.S. License ©2010 Infosecurity.US

Subscribe