Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Virus and Vulnerability Roundup
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Oracle patches 89 holes with quarterly security update

The patches affect versions of its database software from 8i onward.

October 19, 2005 12:00 PM ET

IDG News Service - Oracle Corp. yesterday released a bundle of critical security patches for its software, fixing 89 vulnerabilities in products including its database and application servers and in some PeopleSoft and J.D. Edwards applications. A work-around exists for just one of the vulnerabilties, according to Oracle, which recommends applying the patches as soon as possible.

The patches are part of Oracle's quarterly security update program and affect versions of its database software from 8i onward. Customers covered by Oracle's Extended Maintenance Support or Extended Support plans can download the patches.

The company supplied fixes for 33 vulnerabilities in its database server software, many of them easy to exploit and with wide impact on the confidentiality, integrity or availability of information stored in databases. That is as bad as it gets in Oracle's security rating system.

Oracle patched 14 flaws in its application server software (four of them fixed by the database server patches and 10 requiring further patches), 13 flaws in its Collaboration Suite, 22 in its E-Business Suite and one in its Enterprise Manager software.

Six of the patches are for PeopleSoft or J.D. Edwards EnterpriseOne software. There is a work-around for one of these vulnerabilities, which can be fixed by turning off PSOL Manager until the patch is applied.

One of the security vulnerabilities, known as CAN-2005-0873, was already public, Oracle said. According to the Common Vulnerabilities and Exposures list, it allows remote attackers to inject arbitrary Web scripts or HTML into Oracle Reports Server 10g (9.0.4.3.3) via multiple cross-site scripting attacks. Oracle provides few details of the vulnerabilties fixed by the other patches.

More information on Oracle's latest critical patch update can be found online at http://www.oracle.com/technology/deploy/security/pdf/cpuoct2005.html.

Oracle plans to release its next update on Jan. 17.


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Jump to comments

Viruses

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.