Feeds

Oracle patch batch to fix 59 flaws

TimesTen, Secure Backup and Solaris

Security for virtualized datacentres

Oracle plans to release 59 vulnerability fixes, including 21 for Solaris products, as part of its quarterly patch update later on Tuesday.

The highest severity flaws involve bugs in TimesTen In-Memory Database and Oracle Secure Backup. However a big chunk of Oracle's enterprise software product line will need patching for one reason or another. The updates include security fixes for Oracle Database 11g (and earlier versions of the flagship software), Oracle Application Server, Oracle WebLogic Server, Oracle E-Business Suite as well as enterprise software technology acquired from PeopleSoft, among other packages.

The two new security fixes for the TimesTen In-Memory Database address vulnerabilities that might be remotely exploitable without authentication. Three of the five security fixes for Oracle Secure Backup carry the same critical vulnerability risk. Four of the six Oracle Database Server vulnerabilities might also be exploited without the need to log into vulnerable systems but are accessed as a slight lower risk of 7.8 on the CVSS 2.0 scoring system used by Oracle. The Secure Backup and TimesTen security bugs both hit the maximum security (brown alert) rating of 10.0.

Seven of the 21 Oracle Solaris Products Suite flaws are capable of exploitation without authentication. Affected products in this range include Access Manager / OpenSSO, Solaris, Sun Convergence, Sun Java System Application Server and Sun Java System Web Proxy Server, among others.

Altogether the chance of an Oracle admin escaping patching duties are about as good as running through the Dutch defence in last Sunday's World Cup match without a kick in the shins, as can be verified from the detailed list in Oracle's pre-alert notice here. Tuesday's update from Oracle comes at the same time as the expected publication by Microsoft of four bulletins covering three critical flaws including a Windows Help zero-day vulnerability. ®

Beginner's guide to SSL certificates

More from The Register

next story
Microsoft on the Threshold of a new name for Windows next week
Rebranded OS reportedly set to be flung open by Redmond
Business is back, baby! Hasta la VISTA, Win 8... Oh, yeah, Windows 9
Forget touchscreen millennials, Microsoft goes for mouse crowd
SMASH the Bash bug! Apple and Red Hat scramble for patch batches
'Applying multiple security updates is extremely difficult'
Apple: SO sorry for the iOS 8.0.1 UPDATE BUNGLE HORROR
Apple kills 'upgrade'. Hey, Microsoft. You sure you want to be like these guys?
ARM gives Internet of Things a piece of its mind – the Cortex-M7
32-bit core packs some DSP for VIP IoT CPU LOL
Lotus Notes inventor Ozzie invents app to talk to people on your phone
Imagine that. Startup floats with voice collab app for Win iPhone
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.