Advertisement
Promo

Security threats Toolkit

Oracle to patch 38 flaws

Tom Espiner ZDNet UK

Published: 19 Oct 2009 16:42 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Oracle plans to release an update on Tuesday that will patch 38 vulnerabilities across hundreds of products.

Oracle's Critical Patch Update, scheduled for 20 October, contains fixes for numerous flaws, the company said. Many of the security holes have the maximum score of 10.0 on the common vulnerability scoring system (CVSS), marking them as critical. For example, vulnerabilities affecting Oracle Core RDBMS, Oracle JRockit and Oracle Network Authentication have a CVSS score of 10.0.

"Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Patch Update fixes as soon as possible," said the company in its advance notification of the update.

The business-software maker's flagship product, Oracle database, suffers from 16 flaws that will be patched by the update. Components with vulnerabilities include advanced queuing, application express and authentication.

Other products with flaws addressed by the patches include: Oracle Application Server; Oracle Applications Suite; Oracle E-Business Suite; Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne; Oracle BEA Products; and Oracle Industry Applications Products.

The Oracle update comes a week after Adobe patched 28 holes, and Microsoft plugged Windows 7 flaws in its largest-ever patch release. Like those companies, Oracle usually issues its patch bundles on the second Tuesday of the month, but delayed the October update for a week to avoid coinciding with its Oracle OpenWorld conference.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
4 out of 4 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters