Oracle Issues 36 Patches

Apr 18, 2007

The Critical Patch Update is among the smallest since Oracle began quarterly updates.

Oracle Corp. Tuesday issued its second critical patch update for the year, this time patching 36 security holes in its products – including several that can be exploited remotely by an attacker without authentication.

The most serious of the flaws affects Oracle relational database management system running on Windows, that received a Common Vulnerability Scoring System rating of 7.0 out of 10. This flaw can be exploited remotely by attacker sans a password or user name for authentication.

The CVSS standard, which was created by the Homeland Security Department's National Infrastructure Advisory Council, was adopted by Oracle in October. None of the other vulnerabilities addressed by the Oracle release – besides the flaw affecting the relational database management system - rated higher than 4.2.

There are 13 security fixes for the Oracle Database. In addition, 11 security fixes were issued for Oracle E-Business Suite and Applications, five for Oracle Application Server, one each for Oracle Enterprise Manager, Oracle Secure Enterprise and the Oracle Collaboration Suite. There are also four fixes for JD Edwards EnterpriseOne and Oracle PeopleSoft Enterprise.

The release is among the smallest patch loads in several months. In January, Oracle's critical patch update addressed 51 flaws, while the company's critical patch update last October contained more than 100 security fixes. The next Critical Patch Update is scheduled for July 17.

Eric Maurice, manager of security in Oracle's Global Technology Business Unit, wrote on the company's security blog today that the company's decision to release quarterly updates has improved product maintenance for customers.

"The predictability provided by the - Critical Patch Update - mechanism is very important to Oracle customers," he wrote. "It results in enabling customers to plan for the CPUs and install them in their normal maintenance windows, to avoid undue interruptions in their business-critical systems."

Copyright 2007 by Ziff Davis Media, Distributed by United Press International

Explore further: Android gains in US, basic phones almost extinct

add to favorites email to friend print save as pdf

Related Stories

Bringing the world reboot-less updates

Jan 24, 2014

It's an annoyance for the individual computer user: You've updated your operating system, and now you need to reboot. This is so the computer can switch to the modified source code.

Internet Explorer users are warned against Poison Ivy

Sep 18, 2012

(Phys.org)—More than a few Internet Explorer users stand vulnerable to fresh attacks of Poison Ivy. In the latest headline in the "Internet Explorer has a flaw" saga, a security hole in Internet Explorer ...

Latest Java poison romps on as ok.XXX4.net

Aug 28, 2012

(Phys.org)—Yet another Java-related computer threat, cross-platform, has been nailed by security researchers. An exploit was seen by FireEye researchers on Sunday, being hosted on a domain ok.XXX4.net. ...

Hackers hit Apple in wake of Facebook attack

Feb 19, 2013

Apple on Tuesday said it suffered a cyber attack similar to the one recently carried out against Facebook, but that it repelled the invaders before its data was plundered.

The dangers of too much Java

Jan 31, 2013

Justin Cappos, an assistant professor of computer science and engineering at the Polytechnic Institute of NYU-Poly, has long been wary of the security risks inherent in Java, the programming language developed ...

Recommended for you

Android gains in US, basic phones almost extinct

11 hours ago

The Google Android platform grabbed the majority of mobile phones in the US market in early 2014, as consumers all but abandoned non-smartphone handsets, a survey showed Friday.

Hackathon team's GoogolPlex gives Siri extra powers

Apr 17, 2014

(Phys.org) —Four freshmen at the University of Pennsylvania have taken Apple's personal assistant Siri to behave as a graduate-level executive assistant which, when asked, is capable of adjusting the temperature ...

Microsoft CEO is driving data-culture mindset

Apr 16, 2014

(Phys.org) —Microsoft's future strategy: is all about leveraging data, from different sources, coming together using one cohesive Microsoft architecture. Microsoft CEO Satya Nadella on Tuesday, both in ...

User comments : 0

More news stories

LinkedIn membership hits 300 million

The career-focused social network LinkedIn announced Friday it has 300 million members, with more than half the total outside the United States.

Researchers uncover likely creator of Bitcoin

The primary author of the celebrated Bitcoin paper, and therefore probable creator of Bitcoin, is most likely Nick Szabo, a blogger and former George Washington University law professor, according to students ...

Impact glass stores biodata for millions of years

(Phys.org) —Bits of plant life encapsulated in molten glass by asteroid and comet impacts millions of years ago give geologists information about climate and life forms on the ancient Earth. Scientists ...