[Home]   [Full version]  

Oracle Update to Fix 37 Security Flaws

Apr 12 ,Technology


Thirteen security issues affecting Oracle Database are among those addressed.

Oracle plans to release patches to plug 37 security holes in its products next week, according to a preview of the upcoming Critical Patch Update released April 10.

The update will be made available April 17 and will include 13 security fixes for Oracle Database, two for Oracle Enterprise Manager, and one each for Oracle Workflow Cartridge and the Ultra Search component affect code bundled with Oracle Database.

"[Three] of these vulnerabilities may be remotely exploitable without authentication, i.e. they may be exploited over a network without the need for a username and password," the Redwood Shores, Calif., company reported in the announcement. " - Two - of these fixes are applicable to Oracle Database client-only installations, i.e. installations that do not have the Oracle Database installed."

The update also features 11 security patches for the Oracle E-Business Suite, two of which may be remotely exploited without authentication, the company warned in the announcement. Five security fixes are planned for Oracle Application Server. Other patches address vulnerabilities in Oracle Enterprise Manager and the company's PeopleSoft and JD Edwards Enterprise tools.

The upcoming release will be among the smallest patch loads in several months if it goes ahead as announced. In January, Oracle's critical patch update addressed 51 flaws, while the company's critical patch update last October contained more than 100 security fixes.

Copyright 2007 by Ziff Davis Media, Distributed by United Press International

Related stories:

Oracle Issues 36 Patches
The Critical Patch Update is among the smallest since Oracle began quarterly updates.
Software industry's 'patch culture' attack
An attack from the security chief of software giant Oracle on the so-called culture of patching and bug-ridden products in the software industry has drawn fire from industry observers, citing the comments as hypocritical and naive.
HP's Industry-first Linux Notebook, Linux Reference Architectures and Multi-OS Superdome Server
Enterprise and public sector customers use HP Linux solutions to gain simplicity and value across their infrastructures

HP today showcased its leading innovation with new customers Versaterm and VentureLink, as well as new services and products, including the world's first pre-installed Linux notebook PC from a major hardware vendor and an expanded Linux services professional team.
GridApp Offers Patch Management Service for DBs
GridApp Systems is offering a managed service that will handle the testing and delivery of patches for databases.
Oracle Makes Bid to Streamline Data Auditing
Oracle Audit Vault aims to help simplify data auditing and aid in meeting the regulatory requirements businesses face.
Passlogix and RSA to Combine Authentication Technologies
Passlogix and EMC security division RSA have entered into a strategic partnership to combine RSA's two-factor authentication technology with Passlogix's single sign-on platform.
EMC Acquires Its Way to Juggernaut Status
These days, EMC looks a little like the Energizer Bunny - it keeps going, and going, and going - seemingly unstoppable.
Former OSDL CEO Launches Startup
Collaborative Software Initiative will focus on building noncompetitive, essential software for vertical industries in a collaborative environment to help companies solve their shared IT problems.

News discussion:

Technology news

[Home]   [Full version]