Oracle has announced plans to ship a Critical Patch Update (CPU) with fixes for at least 38 security vulnerabilities in a wide range of database and server products.
The most serious vulnerabilities affect Oracle Core RDBMS, Oracle JRockit and Oracle Network Authentication. Read the Oracle advance notice [oracle.com]