Oracle Issues 41 Security Fixes in Latest CPU

Oracle Issues 41 Security Fixes in Latest CPU

Written By
Brian Prince
Brian Prince
Apr 15, 2008
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Oracle released fixes for a total of 41 bugs in its April Critical Patch Update, including a serious vulnerability affecting Oracle Application Server.

The CPU, Oracle’s second of the year, includes 17 fixes for Oracle Database products, 11 for the Oracle E-Business Suite, six for the Oracle Siebel Enterprise Suite, three for Oracle Application Server, three for the PeopleSoft-JD Edwards Suite and one for Oracle Enterprise Manager.

Oracle endorses role-based access management. Click here to read more.

The most serious of the vulnerabilities affects Oracle Application Server, specifically Oracle Jinitiator, and has a CVSS (Common Vulnerability Scoring System) rating of 9.3. Jinitiator allows a Web-enabled Oracle Forms client application to run within a browser. According to the company’s advisory, the vulnerability applies only to the client portion of Application Server.

“The impact of this vulnerability is limited to Jinitiator; there is no Oracle Application Server impact,” company officials stated in the advisory. “Oracle Jinitiator Versions 1.3.1.15 and later are not affected.”

All three of the vulnerabilities affecting Application Server can be exploited remotely without authentication. Seven of the 11 vulnerabilities affecting Oracle E-Business Suite can be exploited remotely without a user name or password.

January’s CPU featured 26 security fixes for Oracle products. The next CPU is slated to be released July 15.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.