Oracle joins Microsoft with a major security update

Share this article:
Oracle on Tuesday shipped 36 patches in its latest quarterly security update.

For the first time this year, administrators were walloped with Oracle and Microsoft patches on the same day.

Microsoft drops its patches on the second Tuesday of each month, while Oracle delivers theirs on the Tuesday closest to the 15th of January, April, July and October.

The Oracle update includes 15 fixes for the Database Suite, with one of the flaws being remotely exploitable without authentication, according to the advisory.

Oracle also pushed out six patches for the Application Server Suite, four for the Applications Suite, five for PeopleSoft Enterprise and JD Edwards EnterpriseOne and six for the BEA Products Suite.

The most severe vulnerability corrected was one affecting the Apache plugin for Oracle WebLogic Server, formerly BEA WebLogic. The flaw earned a perfect 10 on Oracle's vulnerability scoring system. Most other bugs ranged in the four-to-six range.

Oracle did not issue any fixes for the Collaboration Suite or Enterprise Manager.




Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

More in News

TorrentLocker developers patch error

Victims had been able to restore encrypted files without paying a ransom.

Home Depot: breach risks 56M payment cards, 'unique' malware used

Home Depot confirmed that approximately 56 million payment cards may have been compromised as result of a malware attack.

Gartner: 75 percent of mobile apps will fail security tests through end of 2015

Gartner: 75 percent of mobile apps will fail ...

As BYOD and mobile computing become more critical to business, app downloads will raise security risks.