Feeds

Oracle readies mega-update patching 51 security holes

Fixes span hundreds of products

Remote control for virtualized desktops

Oracle is to release updates on Tuesday that patches 51 security vulnerabilities across hundreds of products.

The update will fix 27 bugs in the Oracle database, the company's flagship product. Five of them can be exploited over a network without the need for a username and password. None of the fixes are applicable to client-only installations of the program.

Tuesday's patch will plug 11 holes in the Oracle Application Server, seven of which are remotely exploitable. Other products being fixed include Oracle E-Business Suite and Applications, Oracle Enterprise Manager and Oracle PeopleSoft Enterprise PeopleTools and JD Edwards EnterpriseOne.

The maximum severity of the of the flaws is 6.8, as measured on version 2 of the Common Vulnerability Scoring System, which uses a scale of 1 to 10.

Oracle generally issues patches every quarter. In July, it issued updates fixing 45 vulnerabilities. ®

Internet Security Threat Report 2014

More from The Register

next story
Webcam hacker pervs in MASS HOME INVASION
You thought you were all alone? Nope – change your password, says ICO
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Meet OneRNG: a fully-open entropy generator for a paranoid age
Kiwis to seek random investors for crowd-funded randomiser
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Reducing the cost and complexity of web vulnerability management
How using vulnerability assessments to identify exploitable weaknesses and take corrective action can reduce the risk of hackers finding your site and attacking it.
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.