Oracle Releases Security Alert for Java Runtime Environment
Posted: 10/2/11 by komz in Etiquetas: ataque denegación de servicio, DoS, oracle, Oracle Critical Patch Update
Current threat level of vulnerabilities by X-Force, IBM.
FOR MORE INFO.
Tal como anunciamos el lunes, Oracle ha liberado su boletin de seguridad el cual presenta 66 nuevos "security fixes" para corregir multiples vulnerabilidades que afectan a muchos de sus productos que a continuacion listamos:
Oracle Database 11g Release 2, version 11.2.0.1 | Database |
Oracle Database 11g Release 1, version 11.1.0.7 | Database |
Oracle Database 10g Release 2, versions 10.2.0.3, 10.2.0.4, 10.2.0.5 | Database |
Oracle Database 10g Release 1, version 10.1.0.5 | Database |
Oracle Audit Vault 10g Release 2, version 10.2.3.2 | Database |
Oracle Secure Backup 10g Release 3, version 10.3.0.2 | Database |
Oracle Fusion Middleware, 11g Release 1, versions 11.1.1.2.0, 11.1.1.3.0 | Fusion Middleware |
Oracle Application Server 10g Release 2, version 10.1.2.3.0 | Fusion Middleware |
Oracle Beehive, versions 2.0.1.0, 2.0.1.1, 2.0.1.2, 2.0.1.2.1, 2.0.1.3 | Fusion Middleware |
Oracle BI Publisher, versions 10.1.3.3.2, 10.1.3.4.0, 10.1.3.4.1, 11.1.1.3 | Fusion Middleware |
Oracle Document Capture, versions 10.1.3.4, 10.1.3.5 | Fusion Middleware |
Oracle GoldenGate Veridata, version 3.0.0.4 | Fusion Middleware |
Oracle JRockit versions, R27.6.7 and earlier (JDK/JRE 1.4.2, 5, 6), R28.0.1 and earlier (JDK/JRE 5, 6) | Fusion Middleware |
Oracle Outside In Technology, version 8.3.0 | Fusion Middleware |
Oracle WebLogic Server, versions 7.0.7, 8.1.6, 9.0, 9.1, 9.2.3, 10.0.2, 10.3.2, 10.3.3 | Fusion Middleware |
Oracle Enterprise Manager Suite Release 10, version 10.2.0.5 | Enterprise Manager Suite |
Oracle Enterprise Manager Real User Experience Insight, version RUEI 6.0 | Enterprise Manager Suite |
Oracle E-Business Suite Release 12, versions 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3 | E-Business Suite |
Oracle E-Business Suite Release 11i, version 11.5.10.2 | E-Business Suite |
Oracle Agile Core, versions 9.3.0.2, 9.3.1 | Oracle Supply Chain |
Oracle Transportation Manager, versions 5.5, 6.0, 6.1, 6.2 | Oracle Supply Chain |
Oracle PeopleSoft Enterprise CRM, versions 8.9, 9.0, 9.1 | PeopleSoft |
Oracle PeopleSoft Enterprise HRMS, versions 8.9, 9.0, 9.1 | PeopleSoft |
Oracle PeopleSoft Enterprise PeopleTools, versions 8.49, 8.50, 8.51 | PeopleSoft |
Oracle Argus Safety, versions 5.0, 5.0.1, 5.0.2, 5.0.3 | Health Sciences Applications |
Oracle InForm Portal, versions 4.5, 4.6, 5.0 | Health Sciences Applications |
Oracle Sun Product Suite | Oracle Sun Product Suite |
Oracle Open Office, version 3.2.1 and StarOffice/StarSuite, versions 7, 8 | Oracle Sun Product Suite |
This Critical Patch Update Pre-Release Announcement provides advance information about the Oracle Critical Patch Update for January 2011, which will be released on Tuesday, January 18, 2011. While this Pre-Release Announcement is as accurate as possible at the time of publication, the information it contains may change before publication of the Critical Patch Update Advisory.
The update addresses 66 vulnerabilities affecting the following software:
Oracle Database Server
Oracle Secure Backup
Oracle Fusion Middleware
Oracle Enterprise Manager Grid Control
Oracle Solaris products
Oracle Applications
Oracle Supply Chain Products Suite
Oracle PeopleSoft and JDEdwards Suite
Oracle Industry Applications
Oracle Sun Products
Oracle Open Office Suite
PRE-RELEASE Oracle January 2011 Critical Patch Update
fuente: oracle.com
Oracle ha hecho oficial el lanzamiento de su Critical Patch Update para el mes de Octubre 2010 en donde corrige 85 vulnerabilidades a lo largo de sus productos. Esta actualiazacion contiene los siguiente parche de seguridad:
* 7 for Oracle Database Server
* 8 for Oracle Fusion Middleware
* 1 for Oracle Enterprise Manager Grid Control
* 6 for Oracle E-Business Suite
* 2 for Oracle Supply Chain Products Suite
* 21 for Oracle PeopleSoft and JDEdwards Suite
* 4 for Oracle Siebel Suite
* 1 for Oracle Primavera Products Suite
* 26 for Oracle Sun Products Suite
* 5 for Oracle Open Office Suite
* 4 for Oracle VM
ORACLE CRITICAL PATCH UPDATE
Desde Vulnerability Team exortamos a los usuarios y administradores revisar las notificaciones y aplicar las actualizaciones necesarias, para ayudar a mitigar los riesgos.
fuente: us-cert.org | oracle.com
Oracle ha anunciado de forma anticipada su Critical Patch Update para el mes de Octubre, el cual solucionará 81 vulnerabilidades. Este parche sera emitido el martes 12 de octubre, coincidiendo con el dia en que Microsoft publicara su Boletin de Seguridad del mes de Octubre
31 de las 81 vulnerabilidades son correspondientes a Oracle Sun Products Suite.