Oracle Issues 36 Patches

April 18, 2007

The Critical Patch Update is among the smallest since Oracle began quarterly updates.

Oracle Corp. Tuesday issued its second critical patch update for the year, this time patching 36 security holes in its products – including several that can be exploited remotely by an attacker without authentication.

The most serious of the flaws affects Oracle relational database management system running on Windows, that received a Common Vulnerability Scoring System rating of 7.0 out of 10. This flaw can be exploited remotely by attacker sans a password or user name for authentication.

The CVSS standard, which was created by the Homeland Security Department's National Infrastructure Advisory Council, was adopted by Oracle in October. None of the other vulnerabilities addressed by the Oracle release – besides the flaw affecting the relational database management system - rated higher than 4.2.

There are 13 security fixes for the Oracle Database. In addition, 11 security fixes were issued for Oracle E-Business Suite and Applications, five for Oracle Application Server, one each for Oracle Enterprise Manager, Oracle Secure Enterprise and the Oracle Collaboration Suite. There are also four fixes for JD Edwards EnterpriseOne and Oracle PeopleSoft Enterprise.

The release is among the smallest patch loads in several months. In January, Oracle's critical patch update addressed 51 flaws, while the company's critical patch update last October contained more than 100 security fixes. The next Critical Patch Update is scheduled for July 17.

Eric Maurice, manager of security in Oracle's Global Technology Business Unit, wrote on the company's security blog today that the company's decision to release quarterly updates has improved product maintenance for customers.

"The predictability provided by the - Critical Patch Update - mechanism is very important to Oracle customers," he wrote. "It results in enabling customers to plan for the CPUs and install them in their normal maintenance windows, to avoid undue interruptions in their business-critical systems."

Copyright 2007 by Ziff Davis Media, Distributed by United Press International


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - not rated yet


April 18, 2007 all stories

Comments: 0

not rated yet
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • GridApp Offers Patch Management Service for DBs
    created May 09, 2007 | popularity not rated yet | comments 0
  • Oracle Update to Fix 37 Security Flaws
    created Apr 12, 2007 | popularity not rated yet | comments 0
  • Software industry's 'patch culture' attack
    created Jun 06, 2006 | popularity not rated yet | comments 0
  • HP's 3Com takeover marks a shot at Cisco
    created Nov 11, 2009 | popularity not rated yet | comments 0
  • IBM scoops up software maker SPSS in $1.2B deal
    created Jul 28, 2009 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • why are you an engineer?
    created 9 hours ago
  • Variable Pitch Propeller mechanism?
    created 13 hours ago
  • Bread Board
    created Nov 14, 2009
  • Student team - building a satellite - want to join - problem:i'm a biotech student.
    created Nov 13, 2009
  • More from Physics Forums - General Engineering

Other News

All eyes on Murdoch as newspapers ponder digital future

Technology / Internet

created 15 hours ago | popularity not rated yet | comments 1

Is Rupert Murdoch bluffing? Making a bold high-stakes gamble that will save the troubled newspaper industry? Or pursuing a pipe dream that can only end in failure?


Road trains may be coming soon to Europe

Road trains may be coming soon to Europe (w/ Video)

Technology / Engineering

created Nov 13, 2009 | popularity 4.8 / 5 (12) | comments 22

(PhysOrg.com) -- Road trains linking vehicles together in a traveling convoy are planned for Europe. With only the lead vehicle being actively driven, the road trains would allow commuters to sleep, read a ...


A system of space solar power system (SSPS)

Japan eyes solar station in space as new energy source

Technology / Energy

created Nov 08, 2009 | popularity 4.8 / 5 (22) | comments 31

It may sound like a sci-fi vision, but Japan's space agency is dead serious: by 2030 it wants to collect solar power in space and zap it down to Earth, using laser beams or microwaves.


Cars sit in traffic on a highway

Netherlands to levy 'green' road tax by the kilometre

Technology / Hi Tech

created Nov 13, 2009 | popularity 3 / 5 (4) | comments 8

The Dutch government said Friday it wants to introduce a "green" road tax by the kilometre from 2012 aimed at cutting carbon dioxide emissions by 10 percent and halving congestion.


Hydrogen milestone moves energy independence one step forward

Hydrogen milestone moves energy independence one step forward

Technology / Energy

created Nov 10, 2009 | popularity 3.9 / 5 (12) | comments 7

(PhysOrg.com) -- Big things often come in small packages. That's certainly the case with the potential created by recent successes in hydrogen research at Idaho National Laboratory.