HomeUpdatesOracle January Patch: Fixes 320 new vulnerabilities

Oracle January Patch: Fixes 320 new vulnerabilities

Oracle will release security updates (January 2025 patch) to fix 320 new vulnerabilities affecting more than 90 products and services across 27 categories .

Oracle vulnerabilities

Product categories include Communications, Construction and Engineering appliances, middleware and servers, as well as products and services belonging to the Oracle E-Business Suite.

According to an announcement (before the updates were released), the vulnerabilities fixed in January patch span the full CVSS severity scale. There are vulnerabilities with low scores and others that are considered critical.

See also: OpenVPN Easy-RSA vulnerability enables Bruteforce

The most critical flaws, with a CVSS score of 9.9 , affect the Oracle Supply Chain product line , Oracle Agile Engineering Data Management version 6.2.1 and Oracle Agile PLM Framework version 9.3.6.

There are still five vulnerabilities (at least) with a CVSS score of 9.8.

Oracle recommends that customers apply the updates as soon as possibleto keep their systems secure.

Earlier in January, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an older Oracle WebLogic Server vulnerability ( CVE-2020-2883 ) to the List of Known Exploitable Vulnerabilities . This vulnerability has been patched for years, but there are still networks that have not applied the updates.

See also: TP-Link buffer overflow vulnerability exploited for code execution

Oracle January Patch: Fixes 320 new vulnerabilities

In recent years, the number of reported vulnerabilities in software systems has been steadily increasing, making regular updates a key part of any organization’s security strategy. This is especially true for large organizations with extensive IT infrastructures, such as those based on Oracle products. The sheer volume and complexity of these systems make them attractive targets for cyber attackers who seek to exploit any weaknesses for financial gain or cyber espionage. Therefore, it is important for organizations to remain vigilant and keep their systems up to date with the latest patches.

See also: ChatGPT Crawler: Vulnerability allows DDoS attacks on websites

It is also important for organizations to have a robust vulnerability management program in place. This includes regular vulnerability assessments, penetration testing, and implementing secure coding practices during software development.

source:www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS