Oracle Issues Critical Security Bug Fixes for Databases

Oracle Issues Critical Security Bug Fixes for Databases, Glassfish, and More

April 18, 2012
By Tim OBrien

If you watched our security feed, you may have noticed this IDG News Service story reporting on a critical security patch from Oracle. Since many of our customers are directly affected by this vulnerability, we thought this announcement was important enough to feature. From the story:

"The upcoming patch batch includes six fixes for Oracle's database, three of which can be exploited remotely without a username and password. Common Vulnerability Scoring System (CVSS) base score for the database bugs is 9 on the system's 10-point scale. Another 11 patches cover Oracle Fusion Middleware, with 9 being remotely exploitable without authentication."

Three important take-aways from this announcement:

Here's a quote from the Oracle Critical Security Patch:

Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply CPU fixes as soon as possible. This Critical Patch Update contains 88 new security fixes across the product families listed below.

If you are affected by this vulnerability, go get this Critical Security Patch Update from Oracle today.

Written by Tim OBrien
Tim is a Software Architect with experience in all aspects of software development from project inception to developing scaleable production architectures for large-scale systems during critical, high-risk events such as Black Friday. He has helped many organizations ranging from small startups to Fortune 100 companies take a more strategic approach to adopting and evaluating technology and managing the risks associated with change.