Oracle issues 'huge' patch update

Fixes for 78 vulnerabilities in quarterly release.

Oracle has put out what has been described as a “huge” quarterly critical patch update, with fixes for 78 vulnerabilities across hundreds of products.

It marks another big patch announcement, following the 66 vulnerability update in January.

The hefty update is largely down to Oracle's acquisition of significant companies like PeopleSoft and Sun Microsystems, as well as its own wide range of products, said Amol Sarwate, Vulnerability Labs manager for Qualys.

“Our top priority goes to patching vulnerabilities that attackers can remotely exploit without authentication and where the affected systems could be exposed to the outside world,” Sarwate said.

“For Sun users this includes nine vulnerabilities that affect Solaris (CVE-2011-2287, CVE-2011-2245, CVE-2011-2294, CVE-2011-2298) SPARC (CVE-2011-2288, CVE-2011-2299, CVE-2011-2307) and Oracle GlassFish Server(CVE-2011-1511, CVE-2011-2260). Protocols that attackers could use for exploitation include SSH, HTTP, SSL and KSSL.”

The next priority for IT managers should be to look at vulnerabilities which could be remotely exploitable but affected products which typically would not be exposed due to network segregation or firewalls, Sarwate said.

This included patches for Oracle Database Server, Grid Control, Enterprise Manager and PeopleSoft.

“While some of the products may have a legitimate business reason to be exposed outside of the corporate network, we strongly advise organisations to access their network infrastructures and prioritise patches based on their exposure,” Sarwate said.

“The [Oracle patch updates] are becoming huge. But due to the diversity of affected products, our guess is that many larger organisations could have specialised teams working on different products in order to make the Oracle quarterly [update] a bit more manageable.”

The next batch of Oracle updates was due for 18 October, which would be the last of 2011.

Head here for Oracle’s announcement and breakdown of affected vulnerabilities.

Copyright © ITPro, Dennis Publishing
Oracle issues 'huge' patch update
Keywords

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read