After Microsoft and Adobe released their largest ever slew of patches last
week, Oracle users will be bracing themselves for something similar, as the
business software giant prepares a whopping 38 security vulnerability fixes this
week.
The firm's quarterly
Critical
Patch Update, set for 20 October, will contain fixes for problems across "
hundreds of products", according to a pre-release announcement.
The product which gets the most attention, as usual, is the Oracle Database,
which has 16 new fixes, including six for vulnerabilities which could be
remotely exploited without the need for authentication.
The update will also feature eight fixes for the Oracle Applications Suite,
including five which could be remotely exploited without the need for username
and password.
The PeopleSoft and JD Edwards suites get four security fixes, while the
update contains six fixes for the BEA Products Suite, the Oracle JRockit product
receiving the maximum
Common
Vulnerability Scoring System (CVSS) base score of 10.0.
"This Critical Patch Update contains 38 security vulnerability fixes across
hundreds of Oracle products. Some of the vulnerabilities addressed affect
multiple products," read an Oracle statement.
"Due to the threat posed by a successful attack, Oracle strongly recommends
that customers apply Critical Patch Update fixes as soon as possible.
Vulnerabilities fixed are scored using the standard CVSS 2.0 scoring."
The security update has been delayed for a week owing to the Oracle OpenWorld
conference last week.
Do you agree?
Have your say on this article