Oracle Plans 78 Security Fixes for Upcoming Critical Update
Oracle has fixes for 78 security vulnerabilities slated for next week as part of its first critical update of the year.
The patches are expected to touch the Oracle Database Server, Fusion Middleware, E-Business suite, Supply Chain, PeopleSoft, JD Edwards, Virtualization, Sun and MySQL products. The most serious of the vulnerabilities is a security issue affecting the company’s Sun product suite, and has a CVSS (Common Vulnerability Scoring System) 2.0 rating of 7.8.
As usual, details of the actual vulnerabilities were scarce in Oracle’s pre-release announcement. However, the company noted that the Sun suite components addressed by the update are GlassFish Enterprise Server, Oracle Communications Unified, Oracle OpenSSO and Solaris. All totaled, the suite is home to 17 of the vulnerabilities set to be fixed in the update. Six of these can be exploited remotely without authentication.
Editor's Pick
The product with the largest number of vulnerabilities expected to be addressed by the update is MySQL. According to Oracle, 27 of the vulnerabilities reside in MySQL Server, including one that can be exploited over a network without the need of a username or password. The Oracle Database Server contains just two vulnerabilities being addressed by the update. Also included in the update are fixes for 11 vulnerabilities in Oracle Fusion Middleware, three in the Oracle E-Business Suite, eight for JD Edwards products, six in PeopleSoft products, three in Oracle Virtualization software and one in the Oracle Supply Chain products suite.
The update is scheduled to be available Tuesday, January 17.
“Some of the vulnerabilities addressed in this Critical Patch Update affect multiple products,” Oracle noted in its pre-update advisory. “Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Patch Update fixes as soon as possible.”
Commenting on this Article is closed.
Today's Most Popular
- Anatomy of a LulzSec Attack 'Singles Out' Web 2.0 Weakness
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
- OPINION: Are Anonymous Members Forged in the Crucible of IT Compliance?
- Google to Notify Users of DNSChanger Infections Ahead of July 9 Deadline
- Facebook Cancellation Malware Disguised As Adobe Update Making Rounds
Most Commented Stories
-
Forget 'Brogrammers,' Women Have The Edge In DEFCON Social Engineering Contest (9)
-
Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops (10)
-
The Internet Crime Complaint Center recently warned of malware targeting travelers connecting to Wi-Fi. When traveling, do you (1)
-
HULK DDoS Tool Smash Web Server, Server Fall Down (4)
-
Report: Diablo III Users Find Accounts Hacked, Gold Stolen And New 'Mystery' Friends (2)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



