Oracle in Patch Mode

Thursday, April 20, 2017 @ 04:04 PM gHale

Oracle’s Critical Patch Update (CPU) for April contains 299 fixes.

Over half of the vulnerabilities are remotely exploitable without authentication. In terms of the rating, 40 of the issues were critical, and 25 had a CVSS score of 10.

Java, Python FTP Injection Hole
Huge Oracle Patch
Oracle’s Patch Update
Exploit Kit Jumps on Old Applications

Oracle Financial Services Applications was the most affected product, receiving fixes for 47 vulnerabilities, with 19 of them rated critical with a CVSS score of 10. Also, 25 of the 47 vulnerabilities may be remotely exploitable without authentication, Oracle’s advisory said.

Oracle’s latest CPU addressed vulnerabilities in 25 applications: MySQL and Retail Applications (39 fixes each), Fusion Middleware (31), Sun Systems Products Suite (21), PeopleSoft (16), Virtualization (15), Berkeley DB (14), Support Tools (13), E-Business Suite (11), Communications Applications (11), Java SE (8), Utilities Applications (7), Primavera Products Suite (7), Hospitality Applications (6), Commerce (3), Database Server (2), Enterprise Manager Grid Control (2), and Secure Backup, Hyperion, Supply Chain Products Suite, JD Edwards Products, Siebel CRM, Health Sciences Applications, and Insurance Applications (1 each).

The most important of the addressed issues relate to the Remote Code Execution flaw in Apache Struts 2 found last month to be exploited in the wild after someone published a proof-of-concept (PoC) exploit. Cisco and VMWare products felt the impact.

Oracle addressed critical bugs in the Solaris component of Oracle Sun Systems Products Suite, MySQL Enterprise Monitor component of Oracle MySQL (Struts 2), Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (Struts 2), Oracle Financial Services Asset Liability Management component of Oracle Financial Services Applications (Struts 2), and Oracle Financial Services Data Integration Hub component of Oracle Financial Services Applications (Struts 2).

Over the past several quarters, Oracle has been patching an increasingly higher number of vulnerabilities with each new CPU. With 276 patches, the July 2016 CPU was the first to include over 250 fixes, but the trend continued each quarter since, with 253 flaws addressed in October 2016, and 270 in January 2017.

Leave a Reply

You must be logged in to post a comment.