HomeSecurityOracle patches 443 vulnerabilities with its new update

Oracle patches 443 vulnerabilities with its new update

Oracle's Critical Patch Update (CPU) , released earlier this week, includes a total of 443 new security fixes .

Oracle

This is a record update, both for the number of bugs it fixes and for the criticality of the vulnerabilities it addresses, since approximately 100 of them have been rated CVSS 9 or higher.

The two most critical vulnerabilities can be exploited remotely in Oracle's SD-WAN Aware and SD-WAN Edge , have been designated as CVE-2020-14701 and CVE-2020-14606 respectively and have received a CVSS score of 10.

Following SAP and Microsoft, Oracle is the third software vendor to patch vulnerabilities with the highest possible CVSS score this week.

Most of the fixes, 60 in number, were for Communications Applications , with 17 of them rated critical. Forty-six of the bugs could be exploited remotely by unauthorized attackers.

Many of the fixed bugs had existed in Communications Applications for years, yet had not been detected even though they posed a significant risk.

oracle

Additionally, 52 updates addressed vulnerabilities in Fusion Middleware, with 48 of them being remotely exploitable without authentication.

Other applications that received fixes include Retail applications (47 patches), MySQL (40 updates), Financial Services applications (38), E-Business Suite (30), Virtualization (25 fixes), Supply Chain (22), and Manufacturing and Engineering applications (20, 15).

Applications that received fewer than 20 fixes include Database Server (19 updates), Enterprise Manager (14), Java SE (11), PeopleSoft (11), Systems (7), JD Edwards (6), Insurance Applications (6), Siebel CRM (5), Health Sciences Applications (4), Commerce (4), GraalVM (4), Food and Beverage Applications (4), GoldenGate (3), Berkeley DB (3), Hyperion (3), Hospitality Applications (1), iLearning (1), Utilities Applications (1), Global Lifecycle Management (1), and TimesTen In-Memory Database (1).

The company stressed the importance of timely application of available patches ,revealing that it continues to receive reports of previously addressed flaws that were actively targeted in malicious attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS