Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Chicks just love a Geek in Uniform.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Sergei Strelec's WinPE
5. Visual C++ Redistributable Runtimes AIO Repack
6. Visual C++ Runtime Installer (All-In-One)
7. McAfee Removal Tool (MCPR)
8. MusicBee
9. Unlocker
10. Flyby11
More >>

top reads

Star How To Skip Windows 11 Hardware Checks & Keep Windows 10 in 2025 - The Ultimate Guide

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11


MajorGeeks.Com » News » October 2012 » Oracle Patch Update to Include 109 Patches

Oracle Patch Update to Include 109 Patches


Contributed by: Email on 10/15/2012 03:09 PM [ comments Comments ]


Buckle up Oracle administrators for 109 patches coming your way tomorrow. Oracle’s quarterly Critical Patch Update is due, and the company is releasing fixes for security vulnerabilities across most of its enterprise products, addressing a host of remotely exploitable flaws. This comes a little more than a month after exploits of a serious zero-day vulnerability in Java were reported, as well as a critical zero-day vulnerability in Java SE.

Seemingly, no product line is spared. Five patches will be released addressing security problems in Oracle Database Server, including one that is remotely exploitable over a network without the need for a username and password, Oracle said. Two of the patches address client-only installations.

Two of these vulnerabilities were reported by Application Security Inc.'s TeamSHATTER research outfit, including a remotely exploitable password cracking flaw in Oracle 11g explained in CVE 2012-3137.


"Even though Oracle closed the issue more than a year ago, they are now providing a more complete and easy-to-implement fix. According to information they have provided us, the new fix will address the vulnerability in all supported releases (11.1.0.7, 11.2.0.2 and 11.2.0.3) and will not require a Client software upgrade," said Esteban Martinez Fayo, researcher with TeamSHATTER. "The original fix that they provided one year ago was just for 11.2.0.3 and requires that all client software be upgraded to 11.2.0.3."

The other vulnerability reported by TeamSHATTER, Fayo said, is a SQL injection bug that would allow DBAs with certain privileges to escalate their privileges.

Admins in charge of Oracle application infrastructures may be in for the busiest time.

Oracle announced it will send out 26 new fixes for Oracle Fusion Middleware, the company’s integration platform. Half of the vulnerabilities being repaired are exploitable remotely without the need for authentication. Oracle Fusion Middleware components being patched are: Oracle Application Server Single Sign-On; Oracle BI Publisher; Oracle Business Intelligence Enterprise Edition; Oracle Event Processing; Oracle Imaging and Process Management; Oracle JRockit; Oracle Outside in Technology; Oracle Reports Developer; Oracle WebCenter Sites; and Oracle WebLogic Server.

Oracle also reports 11 patches for its PeopleSoft and Siebel CRM products (nine and two respectively). There is a remotely exploitable vulnerability being repaired for each.

Two remotely exploitable vulnerabilities are being exploited in MySQL Server; 14 in total.

Oracle is also releasing 18 repairs for its Oracle Sun Products Suite, three remotely exploitable vulnerabilities. Oracle said the affected Sun products include Solaris, SPARC T3, Netra SPARC T3, SPARC T4, Netra SPARC T4, Oracle GlassFish Server, Sun GlassFish Enterprise Server, and Sun Java System Application Server.

Oracle Financial Services Software’s FLEXCUBE Direct Banking and FLEXCUBE Universal Banking are also vulnerable to a remote exploit; 13 patches will be released tomorrow.

Finally, nine vulnerabilities in each of Oracle E-Business Suite and Oracle Supply Chain Products Suite will be repaired. Six remotely exploitable flaws have been discovered in E-Business Suite components, while four have been found in the Supply Chain Products Suite.






« ASUS Maximus V Formula @ Bjorn3D · Oracle Patch Update to Include 109 Patches · Iran rejects US accusations after hacker attack »




Comments
comments powered by Disqus

MajorGeeks.Com » News » October 2012 » Oracle Patch Update to Include 109 Patches

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition