The Register® — Biting the hand that feeds IT

Feeds

Oracle discharges monster bug fix

Three dozen bulletins - multiple critical vulns

Free ESG report : Seamless data management with Avere FXT

It's no-questions-asked overtime for data centre staffers again, after Oracle published its latest monster update batch on Wednesday night.

The October update covers vulnerabilities across Oracle's full software product range which is, of course, extensive. There are 36 bulletins in total. Among them are 15 updates for Oracle Database Suite, six involving Oracle Application Server and four involving E-Business Suite applications. There are a quintet of updates for Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne and six involving BEA application server tech.

The impact of the vulnerabilities addressed by the update varies, but the majority pose a critical risk.

One of the database vulnerabilities lends itself to remote exploitation without authentication. Two of the six Application Server flaws pose a similar risk of allowing hackers to launch attacks across the net, without the need to know either user names or passwords. A brace of Oracle E-Business server security bugs, addressed by the patch batch, also pose a critical danger. Five of the BEA bugs are also remotely exploitable.

Oracle's risk and patching matrix provides a comprehensive overview of the three dozen updates. Although none have been tied to specific hacking attacks or script-kiddie friendly exploit packages, according to security clearing houses such as US CERT and Secunia at least, early patching is still advisable. ®

5 ways to reduce advertising network latency

Whitepapers

Microsoft’s Cloud OS
System Center Virtual Machine manager and how this product allows the level of virtualization abstraction to move from individual physical computers and clusters to unifying the whole Data Centre as an abstraction layer.
5 ways to prepare your advertising infrastructure for disaster
Being prepared allows your brand to greatly improve your advertising infrastructure performance and reliability that, in the end, will boost confidence in your brand.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Email delivery: Hate phishing emails? You'll love DMARC
DMARC has been created as a standard to help properly authenticate your sends and monitor and report phishers that are trying to send from your name..
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?

More from The Register

next story
500 MEELLION PCs still run Windows XP. How did we get here?
Just six months to go: what to do if you don't have $200 per PC
'200 million' fanbois using iOS 7 just a week after release - study
Plus: Most US iDevice users are drinking Cupertino's latest Koolaid
App Store ratings mess: What do we like? Sigh, we dunno – fanbois
How do I know what to download if I don't know what everyone else is doing?
Windows 8 fans out-enthuse Apple fanbois
Redmond allows 81 Win 8 devices to use one user ID, solving side-loading shemozzle
Launchpads, catapults... what a load of - WAIT, there's £15m for grabs?
Quango sprinkles cash on games, animation and trendy meeja types
Apple iOS 7 makes some users literally SICK. As in puking, not upset
'Eye candy really is as bad as classical candy is for the teeth,' writes one
Google reveals its Hummingbird: Fly, my little algorithm - FLY!
Update brings Googleplex one step closer to sentience
Oracle hides ExaLogic price cut
Old price lists prove price halved, so why has Big Red deleted the post announcing it?
prev story