
A new security update has been released by Oracle to fix a critical remote code execution vulnerability that could be exploited by a malicious actor to gain access to the system .
The update addresses 405 new security vulnerabilities.
Oracle has released a list of affected products and recommends that users install the new update immediately.
Below is the list of affected products.
9 new security vulnerabilities were fixed in Oracle Database Server. Of these, 2 vulnerabilities could be exploited by a remote attacker without authentication.
The update also fixes a critical vulnerability in Oracle Global Lifecycle Management, which attackers can exploit using only user credentials.
1 vulnerability in Oracle Secure Backup, which can be exploited remotely by attackers without authentication.
Oracle Communications Applications have also received a large number of fixes, 39 in total, 35 of which could be exploited remotely without authentication.
Oracle Construction and Engineering receives updates for 12 security vulnerabilities, 9 of which can be exploited remotely without authentication.
Among other things, Oracle E-Business Suite is receiving a large number of patch updates, 74 in total, with 71 of them being remotely exploitable.
Oracle Financial Services Applications is receiving 34 new security updates and Oracle Fusion Middleware is receiving 56 new updates. The update addresses 45 new security vulnerabilities affecting Oracle MySQL and 19 for Oracle virtualization server.
