 |
|
|
Oracle Corporation has said that it will soon issue security patches for at least 41 vulnerabilities across hundreds of its database product lines. The major update will be released on Tuesday, April 15.
Of the 17 new security fixes for the Oracle Database, two database vulnerabilities stood out as they have been given the highest, 'critical' rank and can be exploited over a network without a username and password, Oracle announced. The company said that none of the two critical security flaws are applicable to Oracle Database client-only installations, i.e. installations that do not have the Oracle Database installed.
"While this Pre-Release Announcement is as accurate as possible at the time of publication, the information it contains may change before publication of the Critical Patch Update Advisory," Oracle said in its Critical Patch Update Pre-Release Announcement.
Here is the full list of products and versions affected, per Oracle:
* Oracle Database 11g, version 11.1.0.6
* Oracle Database 10g Release 2, versions 10.2.0.2, 10.2.0.3
* Oracle Database 10g, version 10.1.0.5
* Oracle Database 9i Release 2, versions 9.2.0.8, 9.2.0.8DV
* Oracle Application Server 10g Release 3 (10.1.3), versions 10.1.3.1.0, 10.1.3.3.0
* Oracle Application Server 10g Release 2 (10.1.2), versions 10.1.2.0.2, 10.1.2.1.0, 10.1.2.2.0
* Oracle Application Server 10g (9.0.4), version 9.0.4.3
* Oracle Collaboration Suite 10g, version 10.1.2
* Oracle E-Business Suite Release 12, versions 12.0.0 - 12.0.4
* Oracle E-Business Suite Release 11i, versions 11.5.9 - 11.5.10 CU2
* Oracle PeopleSoft Enterprise PeopleTools versions 8.22.19, 8.48.16, 8.49.09
* Oracle PeopleSoft Enterprise HCM versions 8.8 SP1, 8.9, 9.0
* Oracle Siebel SimBuilder versions 7.8.2, 7.8.5
Oracle releases its security patches on a quarterly basis.
© 2007 - 2008 - eFluxMedia