Oracle fixes 101 flaws

Free Press Release
iPhone 3G SEO Local Dating Auto Insurance ...
 

Home | Release Features | Success Stories | Release Tips | Journal | FAQ | Search | Submit Release | Members' Area

News Archive > 2006 > Oct > 17
 Premier News
Oracle released its quarterly Critical Patch Update (CPU) Tuesday, fixing 101 flaws across the company's product line.
For_Immediate_Release:

October 17, 2006 (Press Release) -- Attackers could exploit 45 of them from remote locations without a username or password.

"The most severe issues are SQL injection and buffer overflow vulnerabilities," said Amichai Shulman, CTO of Foster City, Calif.-based Imperva Inc., a data security firm. Attackers can exploit SQL injection flaws to access the core of the database with full administrative privileges, he said, adding, "The troubling thing about this quarter is that several flaws that were patched before seem to have reappeared."

In its Oracle security blog, Chicago-based security firm Integrigy Corp. noted that 45 of the 101 flaws are remotely exploitable.

Overall, the company said, the number of flaws this quarter is high compared to previous CPUs, but includes a similar number of database and application server vulnerabilities. "The spike is due to 35 vulnerabilities in Oracle Application Express (formerly HTMLDB)," the company said.

While the CPU offers little detail on the nature of the flaws, there is more information about the number of flaws and their severity than what database administrators (DBAs) have seen in the past. Oracle announced last week that more detail would be added to the bulletins in response to customer feedback. The company has also adopted the Common Vulnerability Scoring System (CVSS) to rate the severity of its flaws.

Here is a summary of the flaws fixed in the latest CPU:

Oracle Database: The patch contains 63 fixes for the database products, including:

Twenty-two fixes for the Oracle Database itself.
Six fixes for Oracle HTTP Server, five of which attackers could exploit remotely without authentication.
Thirty-five fixes for Oracle Application Express, 25 of which attackers could remotely exploit without authentication.
Oracle Application Server" The CPU contains 14 fixes for Oracle Application Server, 13 of which attackers could remotely exploit without authentication.

Oracle Collaboration Suite: There are no new Oracle Collaboration Suite fixes this quarter.

Oracle E-Business Suite and Applications: The CPU contains 13 fixes for the Oracle E-Business Suite. Attackers could exploit one of these vulnerabilities remotely without a username and password.

Oracle Enterprise Manager: There are no new fixes for Oracle Enterprise Manager in this CPU.

Oracle PeopleSoft Enterprise and JD Edwards Enterprise One: The CPU contains eight fixes for Oracle PeopleSoft Enterprise PeopleTools and Enterprise Portal Solutions, and one fix for JD Edwards EnterpriseOne. Attackers could exploit one of the PeopleSoft flaws remotely without a username and password. The JD Edwards EnterpriseOne vulnerability is not remotely exploitable without authentication.



Email Print SPAM

For more information:

http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1225022,00.html

LEAVE A COMMENT
Title:


Message:
You can use following font styles to enhance your article. (No HTML tags.)
[large]sample[/large] sample
[b]sample[/b]sample
[i]sample[/i]sample
[color=#ff0000]sample[/color]sample
Your name:
Your email: (Please provide a valid email.)
Please read the number in the image:
Publisher: By Bill Brenner, Senior News Writer




Related News
December 20,2007
January 18,2008
March 10,2008
April 29,2008
May 14,2008
September 17,2007
March 12,2008
April 24,2008
May 19,2008
December 5,2007
Submit Press Release
IndustriesCountriesTags

Top Headlines More>>
Travel Certificates for Business Owners
Our 3 day 2 night Travel Certificates are only 0.35 cents each and they come imprinted with any information you want on them. No Hassle, No Timeshare. Travel Business Owners, Real Estate Agents, Auto Dealers, Loan Officers, Retailers, Business Owners or Sales People in ANY business, whether online or offline will benefit from this program. The bottom line is this: giving away...
Water Car - Honest Review Of An Amazing Product
Discover Why The Water Car is 100% Worth the Money. Stan Meyer was an inventor who invented the first water car. Unfortunately Stan Meyer was murdered but his product lives on. Yes, you can run your car on water! Simply by using hydrogen fuel cell technology you can start turning your automobile into the next car that runs on water.
Apple’s MacBook Air is the thinnest laptop in the world as Sony VAIO G11 is the lightest
The Sony VAIO G11 is one model that proves to be the challenger with better battery life and storage than the MacBook Air. MacBook Air is Apple’s pride as VAIO G11 is nothing lesser to Sony. The MacBook Pro’s aluminium shell shrouds the MacBook Air remarkably rendering it a silver shine while its curved edges, to a good extent, vindicates it from the industrial looks.
The Power Of Leading With A Strong Product vs. Leading With The Business
The most common question I get asked by my Zrii business prospects is: How do I bring up my business opportunity to other people? My answer: It Depends! Most network marketers are promptly asked by their uplines to write their infamous list of 100 (or 200 or 300) friends and family names down on a piece of paper and start dialing. Someone’s bound to listen and maybe even buy or join...
A Different Type Of Blog
A different type of blog has just been launched.  Stevie's Unique Shopping Mall really lives up to the it's name. This site offers more than just the usual fare of Amazon and Ebay merchandise. Stevie's Unique Shopping Mall offers a wide range of products such as gift items (nuts, cheese, wine, cigar, gag gifts, etc). They also offer fresh sea food, flags, landscaping rocks, self defense...
Developing A Content Driven Online Marketing Strategy
Swim or sink online. It is more crowded than ever and growing. Learn how to stand out from the billions with a strong and diversified marketing strategy. Businesses are moving at a furious pace to the Internet. Being online is becoming a commodity! Where it used to be "cool" and often expensive to be online has now become "normal". And if you are a savvy shopper, also...
Video Game Tester Job Explosion
The video game industry is currently booming. This is driving up the need for video game tester jobs, in order to beta test unreleased video games in time for Christmas release deadlines.
Infinity Car Price Quotes Made Easy
Comparing Infinity car quotes just got easier with Pasch Consulting Group’s new automotive website designed to assist consumers shopping for the best deal on a new or used Infiniti car. PCG announces the launch of a website dedicated to providing consumers with accurate price quotes on new and used Infiniti cars. The website innovates shopping for an Infiniti car by submitting the...
TEENAGE HIP HOP TRIO FROM HARLEM, SQUARE OFF PRESENTS ‘FRESH 2 DEF’ MIXTAPE HOSTED BY DJ WHOO KID.
(New York, NY) Harlem based rappers Square Off collaborate their freshman mixtape with several of Hip Hop’s most influential figures to collaborate the first installment of series of ‘Fresh 2 Def’ hosted by DJ Whoo Kid and original tracks produced by DJ CMS. Throughout the release, Fresh 2 Def is joined by contributors like, Diddy, Tony Yayo and super producer Teddy Riley...

Sitemap | All News | Daily | Weekly | Monthly | Tags | Industries | Countries | RSS | Add URL | Contact Us

Free Press Release All press release information on this site, including free press release and premier press release, is solely based on what our users submit. Free-Press-Release.com disclaims that any right and responsibility for the information go to the user who submit the press release. Some press release may be confusing without additional explanation. You should contact the provider with any questions about the information presented. In case some press release demages your benefits or violate your rights in any way, please contact us and we'll remove it immediately.
  • Press Release
  • Pub Gratuite
  • Press Release
  • Pub Gratuite