Oracle
Oracle has released over 40 patches this quarter

Oracle patches critical vulnerabilities in major update

April's Critical Patch Update contains 43 fixes

Phil Muncaster

Oracle has released 43 security fixes across its portfolio of products as part of its quarterly Critical Patch Update, including several vulnerabilities marked as 'critical'.

The update includes patches for 16 vulnerabilities in Oracle Database 11g, 10g and 9i. The most serious is a flaw in Oracle Resource Manager, which was given a Common Vulnerability Scoring System (CVSS) score of 9.

Advertisement

Other affected products include Oracle Application Server, which was allocated 12 security fixes, and several BEA products, including two with CVSS scores of 10.

Vulnerabilities in the Oracle JRockit runtime platform and WebLogic Server itself could both be exploited remotely by a hacker to steal information without the need for username or password authentication, Oracle said.

Other fixes were released for Oracle's E-Business Suite and the PeopleSoft Enterprise product line.

"Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply fixes as soon as possible. Until you apply the fixes, it may be possible to reduce the risk of successful attack by restricting network protocols required by an attack," the firm said in a statement.

"For attacks that require certain privileges or access to certain packages, removing the privileges or the ability to access the packages from unprivileged users may help reduce the risk of successful attack."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

Oracle

Oracle update includes 41 security fixes

Vendor will release major bug fix on the same day as Microsoft Patch Tuesday

UK Oracle User Group Conference and Exhibition

Oracle scores highly with users

UK user group survey shows positive feedback

Oracle upgrades Adaptive Access Manager

Latest version lets firms configure their own security settings

Oracle adds social features to CRM

Latest Siebel update contains customer self-service capabilities and social network integration

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file...

Dell Adamo XPS

Dell launches ultra-thin Adamo XPS

World's thinnest laptop will be available by Christmas

Top 10 articles, 6 November 2009

The worst Microsoft products of all time, and a USB...

Iain Thomson

Pirate Bay shutdown could be inspiring online militancy

Recent Swedish attacks raise worrying possibility

Primary Navigation