Oracle releases delayed security patches

Oracle Corp. released security patches this week that plug several vulnerabilities reported last month in its database software and other products.

Customers should download the patches to fix holes in current and past versions of Oracle’s database, application server and management tools, the company said in a security bulletin Tuesday. It described the holes in its database and application server as “high risk,” since a hacker could potentially exploit them to access a server without needing a user account, Oracle said.

Many of the holes were discovered in January by security specialist David Litchfield of Next Generation Security Software Ltd. in Surrey, England, who has criticized Oracle for not releasing the patches sooner. They were ready for release more than two months ago, according to Litchfield, but Oracle delayed their release while it prepared a new system for releasing security patches.

Two weeks ago, Oracle switched to a new, monthly cycle for releasing patches.

Tuesday’s bulletin lists all the affected products, which include the Oracle8i, Oracle9i and 10g versions of its database; the Oracle9i and 10g versions of its application server, and Enterprise Manager Grid Control 10g and Enterprise Manager Database Control 10g. Exact version numbers are listed in the bulletin, at www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf.

Customers of the Oracle Collaboration Suite and Oracle E-Business Suite 11i were advised to also patch the database and application server components of those products.

Would you recommend this article?

Share

Thanks for taking the time to let us know what you think of this article!
We'd love to hear your opinion about this or any other story you read in our publication.


Jim Love, Chief Content Officer, IT World Canada

Featured Download

Featured Articles

Cybersecurity in 2024: Priorities and challenges for Canadian organizations 

By Derek Manky As predictions for 2024 point to the continued expansion...

Survey shows generative AI is a top priority for Canadian corporate leaders.

Leaders are devoting significant budget to generative AI for 2024 Canadian corporate...

Related Tech News

Tech Jobs

Our experienced team of journalists and bloggers bring you engaging in-depth interviews, videos and content targeted to IT professionals and line-of-business executives.

Tech Companies Hiring Right Now