Feeds

Oracle e-biz suite needs patching

Get to it, sharpish

  • alert
  • submit to reddit

Intelligent flash storage arrays

Users of Oracle e-business suite applications must patch systems following the discovery of multiple vulnerabilities. Unpatched Oracle E-Business Suite 11i and Oracle Applications 11.0 packages are subject to Multiple SQL injection flaws that could be used to manipulate database entries, Oracle warns.

In the hands of knowledgeable crackers, these vulnerabilities could be remotely exploited simply by using a browser and sending a specially-crafted URL to the web server. Oracle E-Business Suite 11i, 11.5.1 up to 11.5.8 are affected. Users of 11.5.9 and above are safe. All versions of Oracle Applications 11.0 are vulnerable.

There's no interim workaround, so users are strongly advised to apply Oracle's patch. The "critical" flaws were discovered by researchers at security tools firm Integrigy, which specialises in developing intrusion prevention software for Oracle applications. Oracle shops with Internet-facing application servers are particularly at risk, it says.

Oracle’s advisory is here (PDF). ®

Related stories

Oracle discounts revealed in court
Oracle slashes PeopleSoft offer
Oracle 9i Database, Ap Server bust six ways to Sunday
How to hack unbreakable Oracle servers

Top 5 reasons to deploy VMware with Tegile

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.