Commentary
Ready, Set, Patch Your Oracle Software
On Tuesday, Oracle is set to release a bevy of patches for Oracle Database and a handful of other Oracle software.On Tuesday, Oracle is set to release a bevy of patches for Oracle Database and a handful of other Oracle software.The patch update is part of Oracle's quarterly patch cycle, and the affected products go beyond its database and include its Oracle TimesTen In-Memory Database, Oracle Application Server, Oracle E-Business Suite, Oracle Enterprise Manager, Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne, as well as Oracle BEA Products.
First, the good news: None of the 11 patches slated for Oracle databases fix vulnerabilities that are remotely exploitable. That is, attackers must be logged in to conduct an attack. Now the not-so-good news: Nine fixes for Oracle Application Server can be exploited by hackers who are not logged in. The same is true for a number of the updates on deck for Oracle WebLogic Server.
More Security Insights
White Papers
- The BlackBerry PlayBook tablet's Good Bones - by BlackBerry
- New Visual and Wizard-Driven Paradigms for Exploring Data and Developing Analytic Workflows
Reports
More >>Webcasts
- Outsourcing Security: What Every Potential Cloud Security Customer Should Know
- Maximize ROI with Database Consolidation onto Private Clouds
Oracle's Critical Patch Update (CPU) Pre-Release Announcement is available here. The Oracle quarterly patch cycle started about four years ago, as a way for Oracle to help lower the cost and aggravation associated with applying software patches.
While many of these vulnerabilities have been rated as critical, it's not likely that most organizations will rush to patch. Early this year database security vendor Sentrigo asked a few hundred Oracle database professionals if they have ever installed an Oracle CPU and 67.5% said they had never applied an Oracle CPU.
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. | |
|
|
T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting! |
Subscribe to RSSResource Links
This Week's Issue
Technology Whitepapers
- Mobile BI: Actionable Intelligence for the Agile Enterprise
- Creating the Enterprise-Class Tablet Environment - by Yankee Group
- How To Regain IT Control In An Increasingly Mobile World - by BlackBerry
- The BlackBerry PlayBook tablet's Good Bones - by BlackBerry
- New Visual and Wizard-Driven Paradigms for Exploring Data and Developing Analytic Workflows
Featured Resource
This is your portal to all the news, product information, technical data, and other information related to the topic of computer user authentication and certification. Visit us to find out how to ensure that computer users are who they say they are.
Learn More












