View all newsletters
Receive our newsletter - data, insights and analysis delivered to you
  1. Technology
  2. Cybersecurity
January 16, 2012updated 22 Aug 2016 11:24am

Oracle plans mammoth security update

78 vulnerabilities across hundreds of products will be fixed, Oracle says

By Steve Evans

Enterprise software giant Oracle has announced a huge security update that will fix a number of vulnerabilities across its product range.

The patch will fix vulnerabilities in Oracle products, with some flaws affecting a number of different products. Oracle puts the figures at 78 vulnerabilities stretching across hundreds of products.

Affected products include Oracle Database 10g and 11g, Fusion Middleware 11g, Application Server 10g, WebLogic Server, PeopleSoft Enterprise CRM, HRM and PeopleTools, JDEdwards, MySQL and Oracle Sun Product Suite.

The vulnerabilities exposed in Oracle Database Server are remotely exploitable without authentication, Oracle said, which means they could be exploited over a network without the need for a username and password.

MySQL also gets a lot of holes plugged – 27 vulnerabilities in total are due to be fixed, one of which can also potentially be exploited without authentication.

"A Critical Patch Update is a collection of patches for multiple security vulnerabilities. This Critical Patch Update contains 78 new security vulnerability fixes across hundreds of Oracle products. Some of the vulnerabilities addressed in this Critical Patch Update affect multiple products," Oracle said in a statement.

"Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Patch Update fixes as soon as possible," the statement added.

Content from our partners
Powering AI’s potential: turning promise into reality
Unlocking growth through hybrid cloud: 5 key takeaways
How businesses can safeguard themselves on the cyber frontline

The full list of affected products can be found here.

Oracle has come under fire in the past for its patching strategy, with Amichai Shulman, CTO at security firm Imperva, saying the patching process "needs fixing".

Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how Progressive Media Investments may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.
THANK YOU