Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

10/17/2018
05:25 PM
50%
50%

Oracle Issues Massive Collection of Critical Security Updates

The software updates from Oracle address a record number of vulnerabilities.

Updated: 10/18/2018 to correct Onapsis blog information.

Oracle this week issued a Critical Patch Update (CPU) encompassing 301 separate updates spread across the entire Oracle family of products. While not every update is marked "critical," in all they represent a variety of vulnerabilities that Oracle recommends all customers patch as quickly as possible.

According to Onapsis, this marks one of the largest number of vulnerabilities in an Oracle CPU. In its analysis of the CPU, Onapsis says that 28 flaws share the highest-level criticality score — 9.8 — from the Common Vulnerability Scoring System (CVSS) and that more than half of the vulnerabilities lie in business-critical applications.

Waratek issued a guidance statement focusing on programming capabilties, noting that "One-third of the 12 new Java SE bugs carry a severity rating of high or critical; 11 of the 12 can be remotely exploited. Eight of the 12 new WebLogic vulnerabilities are critical."

For more, read here, here, and here.

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
KellimWorthington
50%
50%
KellimWorthington,
User Rank: Apprentice
11/29/2018 | 12:47:53 AM
update
i didn't know much detail about this issues in oracle i am new database this i didn't have much knowledge this is why i don't know what is the issue if anyone full then tells me about this because i wanted to do my university assignment for me on any topic related to database and its features.
markgrogan
50%
50%
markgrogan,
User Rank: Strategist
12/18/2018 | 10:13:58 PM
Fix and Patch
I wonder if it's a better idea to release the patches or just blast them all out at one shot so that people can download all the fixes at one shot. It makes for  a shorter down time I reckon? But honestly, the amount of patches that are being released by Oracle right now, it sort of puts a bit of a dampener if you think about just how secure your system has been... Well.. At least they are doing something about it and fixing it and letting their users know I suppose! 
ThomasMaloney
50%
50%
ThomasMaloney,
User Rank: Apprentice
12/21/2018 | 4:00:25 AM
Do not take the risk
Some users are to complacent when it comes to system updates. Since these updates often take a lot of time to complete, users become reluctant to complete them. This opens up the opportunity for their systems to be come vulnerable and they are letting themselves become exposed to threats.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/25/2020
9 Tips to Prepare for the Future of Cloud & Network Security
Kelly Sheridan, Staff Editor, Dark Reading,  9/28/2020
Malware Attacks Declined But Became More Evasive in Q2
Jai Vijayan, Contributing Writer,  9/24/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-17098
PUBLISHED: 2020-09-30
Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication credentials. This issue affects: August Connect Wi-Fi Bridge App version v10.11.0 and prior version...
CVE-2020-15731
PUBLISHED: 2020-09-30
An improper Input Validation vulnerability in the code handling file renaming and recovery in Bitdefender Engines allows an attacker to write an arbitrary file in a location hardcoded in a specially-crafted malicious file name. This issue affects: Bitdefender Engines versions prior to 7.85448.
CVE-2020-5132
PUBLISHED: 2020-09-30
SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN au...
CVE-2020-15216
PUBLISHED: 2020-09-29
In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revisio...
CVE-2020-4607
PUBLISHED: 2020-09-29
IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper input validation. IBM X-Force ID: 184884.