Printer Friendly
The Free Library
19,607,059 articles and books
Member login
User name  
Password 
 
Join us Forgot password?

Critical patches issued for Oracle products


Oracle on Tuesday issued 41 patches to address vulnerabilities in its products, the most critical of which could allow an attacker to gain complete control of backup systems, databases or web applications.

“There are quite a few critical or high-risk vulnerabilities in this patch,” Amichai Shulman, CTO (Chief Technical Officer) The executive responsible for the technical direction of an organization. See CIO and salary survey.  of Imperva, told SCMagazineUS.com Wednesday. “Many more than we are used to seeing in previous ones.”

The 41 patches are listed as critical overall and Oracle strongly recommended users apply fixes as soon as possible. Five of the vulnerabilities – four affecting the product Secure Backup (for Windows) and one affecting WebLogic Server -- were listed as a 10 on Oracle's one to 10-point Common Vulnerability Scoring System Noun 1. scoring system - a system of classifying according to quality or merit or amount
rating system

classification system - a system for classifying things
 (CVSS CVSS Common Vulnerability Scoring System
CVSS Currumbin Valley State School (Gold Coast, Australia) 
).

Secure Backup is a product aimed at establishing a regular policy-based encrypted backup of all databases in an enterprise. The four vulnerabilities in this product, each receiving a 10 rating, affect Windows versions See Windows.  of the product and could enable an internal attacker to gain complete control of backup system without any required credentials.

“Anyone within the organization with network access to a Secure Backup system can do that,” Shulman said.

Five additional vulnerabilities in Secure Backup, all rated five on the CVSS, also were patched.

Also listed with a 10 rating is a vulnerability in Oracle's WebLogic Server. Oracle acquired this product with the purcahse of enterprise infrastructure software company BEA Systems BEA Systems, Inc. (NASDAQ: BEAS) is one of the major companies developing enterprise infrastructure software. BEA makes middleware, products that help software run on top of databases.  in January 2008. The implication of this vulnerability is that it could enable an external attacker to take complete control over a web application, Shulman said.

Four other vulnerabilities were identified in the BEA BEA - Basic programming Environment for interactive-graphical Applications, from Siemens-Nixdorf.  product suite affecting WebLogic Portal and WebLogic Server, rated from 2.6 to 6.8 on the CVSS.

Ten vulnerabilities were patched for the popular Oracle Database. These are listed from 1.7 to 5.5 on the CVSS, but Shulman said they pose a high risk to organizations because they could enable an attacker to potentially take control of databases.

Patches also were issued for vulnerabilities in the following products: Oracle TimesTen Database, (one vulnerability rated 7.5 on the CVSS), Oracle Application Server (four vulnerabilities rated 2.1 to five), Oracle Collaboration Suite An integrated package of applications from Oracle that provides common searching, directory services, single sign-on and authentication for e-mail, voicemail, calendaring and file management content.  (one vulnerability rated four), Oracle E-Business Suite A group of integrated Internet-based applications from Oracle. Introduced in 2001 as Version 11i, it includes modules for CRM, finance, human resources, supply chain management as well as applications for business intelligence.  (four vulnerabilities rated one to 5.5), Oracle Enterprise Manager (one vulnerability rated 5.5), and PeopleSoft and JD Edwards Suite (six vulnerabilities rated four to 6.5).
Copyright 2009 SC Magazine
No portion of this article can be reproduced without the express written permission from the copyright holder.
Copyright (c) Mochila, Inc.

 Reader Opinion

Title:

Comment:



 

Article Details
Printer friendly Cite/link Email Feedback
Author:Angela Moscaritolo
Publication:SC Magazine
Date:Jan 14, 2009
Words:383
Previous Article:Microsoft lends removal help to fend off worm outbreak
Next Article:New spam, phishing attacks center on Obama inauguration



Related Articles
Merant improves change management for Oracle APPS.
Patch panic.
Oracle monthly patches.
GRIDAPP/MIRO CONSULTING PARTNER SIMPLIFY ORACLE LICENSING.
FIRST FRENCH HOSING PROVIDER DEPLOYS BLUE LANE PATCHPOINT.
GRIDAPP SYSTEMS LAUNCHES PATCHWORKS FOR PATCHING DATABASES.
GRIDAPP DEBUTS CLARITY 4.0 ADVANCED DATABASE AUTOMATION.
Enterprise Database Security - A Case Study
Microsoft pushes out 11 patches for 26 flaws
Oracle joins Microsoft with a major security update

Terms of use | Copyright © 2012 Farlex, Inc. | Feedback | For webmasters | Submit articles