HomeSecurityOracle fixes 167 vulnerabilities with Critical Patch Update

Oracle fixes 167 vulnerabilities with Critical Patch Update

Oracle 's January 2015 critical security update focuses on fixing a total of 167 vulnerabilities found in 48 of its products

Oracle

The patches were released on Tuesday, and the most serious of the issues received the maximum severity rating, according to the second version of the Common Vulnerability Scoring System (CVSS).

Database security expert David Litchfieldsays that 11 of the bugs fixed in this security update have been identified and reported by him, and one of them stands out in terms of risk.

In a tweet on Monday, it said the bug was discovered while checking a customer's systems. It initially believed there had been a previous attack and that the attacker had installed a backdoor.

Upon closer inspection, Litchfield discovered that the backdoor came from Oracle and was part of a seeded installation of its eBusiness Suite. Specifically, it granted administrator privileges to regular users, meaning that any user with sufficient knowledge could gain access to the databases.

According to the company's announcement about the updates, one of the products affected by such a serious vulnerability is Java Standard Edition (SE).

Overall, the program is set to receive 19 fixes, with 14 of them being particularly significant because they address vulnerabilities that pose a risk of remote exploitation.

The developer states that these vulnerabilities would allow an attacker to exploit them without a username and password.

Other Java components included in the list of updates are Java SE Embedded and JRockit.

The product that received the most attention is Oracle Fusion Middleware, for which 35 new security updates are being released, with most of them (28) fixing remote exploit vulnerabilities, without requiring authentication of the potential attacker.

19 components of the product are affected by the vulnerabilities, including Oracle Forms, Oracle HTTP Server, Oracle OpenSSO , and Oracle Security Service. The highest CVSS baseline score affecting these components is 9.3.

Next in line is Oracle's Sun Systems Products Suite, which receives 29 security updates for components such as Fujitsu M10-1, M10-4S Servers, M9000 Servers, Solaris, Solaris Cluster , and SPARC Enterprise M3000.

Ten of the vulnerabilities allow remote exploitation without authentication. The most important security issue received the maximum score of 10.

The company advises users to install the updates as soon as possible to avoid the risk of attack.

The Critical Patch Update is released by Oracle on a quarterly basis. This year it is scheduled for January 20 , April 14 , July 14 , and October 20 .

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS