Oracle preps summer patch cluster
45 updates equal overtime for sysadmins
Customer Success Testimonial: Recovery is Everything
Oracle is preparing to release 45 security patches on Tuesday 15 July as part of its quarterly update cycle.
The updates cover unspecified security bugs across multiple Oracle products including its Oracle Database, Application Server, E-Business Suite and PeopleSoft business applications. Some of the updates address vulnerabilities in multiple products.
Eleven of the planned security updates include patches for versions of Oracle's database. Fortunately none of the flaws lend themselves to remote exploitation without requiring login credentials.
The same can't be said for the nine new security fixes for Oracle Application Server. All nine are capable of being exploited by hackers without login credentials, Oracle warns. Three of the seven updates for Oracle WebLogic Server carry the same risk.
Oracle rates the most severe of this quarter's patch batch (involving the flaws in Application Servers and WebLogic Server) at 6.8 out of 10 - pretty critical - according to the Common Vulnerability Scoring System (CVSS), a cross-industry initiative designed to standardise vulnerability ratings. More details can be found in Oracle's pre-release announcement here. ®
COMMENTS
Still so many more patches to go
Why anyone purchases Oracle products is beyond me. As a contracted pen tester, it is a product which causes nightmares for me. Working ways to mitigate the holes without taking a bite out of a budget is a big challenge. Hurry up Oracle.... I'd like to take a vacation!
Overtime?
What overtime? Companies like mine clamping down on overtime, these patches will be put in by us first thing in the morning or "time in lieu", I'm afraid!

IT infrastructure monitoring strategies
Agentless Backup is Not a Myth
Top 10 SIEM implementer’s checklist
Steps to Take Before Choosing a Business Continuity Partner
Enabling efficient data center monitoring