ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/registration.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Oracle to issue 45 security patches

The vendor’s quarterly round of security patches looks set to focus on quantity as opposed to severity ratings.

By Miya Knights, 11 Jul 2008 at 17:08

Oracle has said it will release 45 critical security fixes next Tuesday, promising to keep database and IT security administrators busy.

But they may be surprised to find that despite the large number, Oracle has said none of the patches can be exploited over a network without a user name and password.

This has led some to question the true meaning of the regular patching cycle, known as Oracle’s Critical Patch Update (CPU). Oracle describes the quarterly CPUs as “the primary means of releasing security fixes for Oracle products to customers with valid support contracts.”

And recent research carried out among Oracle users groups by security firm Sentrigo found that two thirds of the 305 database administrators, consultants and developers surveyed had never installed Oracle's CPU.

Nevertheless, the CPU includes 11 database fixes that affect a number of versions within the 11g, 10g and 9i releases.

Among the affected products are Oracle’s TimesTen in-memory database, Oracle Application Server, a number of PeopleSoft Enterprise products, Oracle Enterprise Manager Database Control, E-Business Suite, and WebLogic Server, which it acquired by purchasing BEA Systems. There are no new patches for Oracle’s J.D. Edwards suite of products.

Despite debate over their importance, Oracle said three of the seven WebLogic Server patches and all nine for Oracle Application Server regard vulnerabilities that can be exploited with no authentication needed.

More details on the CPU is available via Oracle’s pre-CPU notice. The full patches will be released next Tuesday, 15 July.

Email to a friend

Print this page

Social Bookmark this article: What is this?

Be the first to comment on this article

You need to Login or Register to comment.

advertisement
advertisement

    Latest News Videos in Security

Video: Q&A with Richard Archdeacon, Symantec

Play Video: Q&A with Richard Archdeacon, Symantec   Play

IT PRO speaks to Richard Archdeacon, director, global services, at the information security software vendor Symantec.

 

    White papers

Want more background on today's hottest IT trends?

Visit IT PRO's white paper library for more on virtualisation, encryption and other topics.

    Register for IT PRO

You'll get exclusive member benefits including free white papers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Advertisement