Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Applications
    • Applications
    • Cybersecurity
    • Database
    • Servers

    Oracle Plans 73 Bug Fixes in Quarterly Critical Patch Update

    Written by

    Fahmida Y. Rashid
    Published April 15, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Oracle is delivering patches for almost every product in its portfolio in its quarterly update next week. April’s update package is much larger than the January update where 66 issues were fixed, but this time Oracle seems to be focusing less on its core database business.

      Oracle plans to fix 73 security vulnerabilities, including six issues in its flagship database software in the next Critical Patch Update, the company said in its CPU pre-release announcement on April 14. Of the fixed issues, Oracle classified 36 vulnerabilities as critical, or issues that may be exploited remotely without requiring a username or password.

      April’s CPU will contain updates to Oracle Database Server11g and 10g, Oracle Fusion middleware, Oracle Enterprise Manager Grid Control, Oracle Siebel CRM, and Oracle Industry Applications. All the suites, E-Business, Supply Chain Products, PeopleSoft and JD Edwards, will be updated. There will also be security fixes addressing security flaws in Open Office 3, Star Office/Star Suite 7 and 8, and the Oracle Sun product suite, including Solaris and some Java server software, according the Oracle’s pre-release announcement.

      Just like the last CPU in January, there will be six database fixes, of which two are considered critical. Similar to the January update, the vulnerabilities fixed are in components not commonly implemented in many environments, such as database vault and UIX.

      The small number of database fixes despite the overall large size of the CPU raised some flags. “As Oracle continues to get further and further away from being a database-only vendor, their attention and dedication to fixing vulnerabilities on the database platform continues to move in a downward trend,” Alex Rothacker, director of security research for TeamSHATTER, the research arm of Application Security, told eWEEK.

      TeamSHATTER currently has ten open reported database vulnerabilities with Oracle, most of which are classified as a “pretty high risk level,” Rothacker said. There are other researchers who regularly submit their vulnerability findings, so it was likely that were other “potentially critical vulnerabilities” from other researchers that Oracle is not dealing with, Rothacker said.

      There will be nine fixes for Oracle Fusion middleware, of which six are critical. The middleware patches will include fixes to WebLogic and JRockit. Of the 18 vulnerabilities fixed in the Oracle Sun products suite, seven will be critical. The affected Oracle Sun products including Java Dynamic Management Kit, Open SSO Enterprise, Sun Java System Access Manager, Solaris, Sun GlassFish Enterprise Server, Sun Java System Application Server, Sun Java System Access Manager Policy Agent and Sun Java System Messaging Server. There are also security holes that affected Oracle iPlanet Web Server, formerly Sun Java System Web Server.

      Oracle assigns a standard CVSS base score to each bug fix to determine severity. The Common Vulnerability Score System considers the impact of a successful attack in terms of confidentiality, integrity and availability as well as the preconditions required to exploit the security flaw. The bugs affecting JRockit in Oracle Fusion and the Sun GlassFish Enterprise Server and Sun Java System Application Server included in the Oracle Sun Products suite all have a CVSS score of 10, making them most critical.

      There are 14 new security fixes for the PeopleSoft suite, of which one is critical. Of the eight new patches for JD Edwards, 7 are flagged as critical and all three Siebel CRM patches are critical. Eight issues will be addressed in Oracle Open Office Suite, of which seven are critical.

      There are four new fixes in the e-business suite, one in supply chain products suite, and one in industry applications, but none of them are critical.

      Java SE and Java for Business client software is not expected to be updated in this CPU. Oracle still has a separate update cycle for most client-side Java products, even though it appears that there will be some Java updates as part of the CPU scheduled for Oct. 18. The next scheduled Java update is June 7, and the next Oracle CPU is a month later, on July 19.

      This quarter’s CPU is expected on April 19.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×