Oracle to issue 41 security patches
Vulnerabilities, of which 15 are severe, are across 'hundreds' of its products
Computerworld - Oracle Corp. will issue 41 security patches next Tuesday addressing vulnerabilities across "hundreds" of its products, the company said in a pre-release announcement.
More than 15 of those patches address flaws that were described by the company as being remotely executable without the need for authentication -- a class of vulnerability to which Oracle usually assigns its highest severity rating. Of these, nine are slated for Oracle Secure Backup, two for its Application Server product and five for its BEA Product Suite.
The company's Critical Patch Update next week will also include fixes for 10 vulnerabilities in its database products. None of these exploits, however, can be taken advantage of remotely without the attacker having access to a username and password first, the company said.
Among the affected products that were listed by Oracle in its pre-announcement were multiple versions of its database going back to Oracle database 9i, its E-business suite products and several versions of Oracle's WebLogic Server and Portal products.
The number of patches being released by Oracle in this round is about the same as the last quarter, when the company issued 36 security fixes.
By Oracle's standards those number are relatively small. There have been occasions when the company has issued considerably more patches in its quarterly updates. Its January 2006 update had 82 patches, while the same year's October update had 101.
As with every release, Oracle is imploring administrators to install the patches as soon as possible. But if history is any indication, a large number of the database patches, at least, are unlikely to be installed in a hurry.
A study of 305 database administrators released in January 2008 by security vendor Sentrigo Inc. found that two-thirds of those surveyed did not install Oracle's security patches at all, no matter how critical the vulnerabilities were.
Most appeared to be reluctant to bring production environments down for any length of time to implement security patches and were also concerned about the possibility of the fixes breaking applications.
Read more about Malware and Vulnerabilities in Computerworld's Malware and Vulnerabilities Topic Center.
- The 20 Best iPhone/iPad Games of 2013 So Far
- 9 Steps to Build Your Personal Brand (and Your Career)
- 7 Consumer Technologies Coming to an Enterprise Near You
- 11 Signs Your IT Project is Doomed
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Security for Virtualization Learn more.
- When Malware Goes Mobile: Causes, Outcomes and Cures Cybercriminals are increasingly setting their sights on smartphones and other mobile devices. Learn about platform-specific policies and strategies you can employ to protect...
- Harness IT -- An Introduction to Business Intelligence Solutions Learn the key selection criteria required to provide your organization with the capability to address structured data, unstructured data and mobile demands so...
- Business Intelligence Shows its Smarts Today's Business Intelligence (BI) tools provide a new way to think about data with self-service capabilities and user-friendly analytics that can be used...
- Becoming An Analytics Driven Organization Join us on Tuesday, June 18, 2013, 11:00 AM EDT and learn how your agency can create an analytics culture that will enable...
- 3 Reasons Why Sepaton is the World's Fastest Backup Solution Leading analyst, Storage Switzerland learns how Sepaton backs up and deduplicates massive data volumes while maintaining the industry's fastest performance - all in... All Malware and Vulnerabilities White Papers | Webcasts