Oracle joins Microsoft with a major security update

Share this article:
Oracle on Tuesday shipped 36 patches in its latest quarterly security update.

For the first time this year, administrators were walloped with Oracle and Microsoft patches on the same day.

Microsoft drops its patches on the second Tuesday of each month, while Oracle delivers theirs on the Tuesday closest to the 15th of January, April, July and October.

The Oracle update includes 15 fixes for the Database Suite, with one of the flaws being remotely exploitable without authentication, according to the advisory.

Oracle also pushed out six patches for the Application Server Suite, four for the Applications Suite, five for PeopleSoft Enterprise and JD Edwards EnterpriseOne and six for the BEA Products Suite.

The most severe vulnerability corrected was one affecting the Apache plugin for Oracle WebLogic Server, formerly BEA WebLogic. The flaw earned a perfect 10 on Oracle's vulnerability scoring system. Most other bugs ranged in the four-to-six range.

Oracle did not issue any fixes for the Collaboration Suite or Enterprise Manager.




Share this article:

Sign up to our newsletters

More in News

Report: UK police push for required mobile phone PWs

The Metropolitan Police have reportedly lobbied for two years to enact the standard.

JPMorgan Chase customers targeted in massive phishing campaign

JPMorgan Chase customers targeted in massive phishing campaign

Roughly 500,000 emails have been sent out so far as part of a massive multifaceted phishing campaign targeting customers of JPMorgan Chase.

Study: Organizations lack training, budget to thwart insider threats

Study: Organizations lack training, budget to thwart insider ...

Of the 355 IT and security professionals surveyed, a majority indicated that they were ill-equipped to thwart a possible insider threat.