Skip to content

Enterprise software, read for what it costs and who signs for it.

Security

Oracle shipped 673 patches. Six maximum-severity flaws needed no login.

The Oracle Critical Security Patch Update shipped 673 patches across 17 product families, CIO reported.

ERP LEADERS news desk · · First reported by CIO · Edition no. 10
Photo: DronePhotographer / Wikimedia Commons, CC0 · original

E-Business Suite takes 159 patches, while Fusion Middleware requires 153.

All six flaws rated 10 out of 10 can be exploited remotely without a login, according to CIO. Five sit in Fusion Middleware components: Access Manager, Forms, Internet Directory, Platform Security for Java and WebLogic Server. The sixth, CIO reported, is in Hyperion Financial Management, the consolidation tool finance teams use to close the books.

CIO counts 78 Fusion Middleware flaws and 19 E-Business Suite flaws that need no authentication to exploit. Thirteen more Fusion Middleware flaws score 9.9.

Oracle says the six maximum-severity flaws are not marked as exploited in the wild. Oracle's advisory states: "Product releases that are not under Premier Support or Extended Support are not tested for the presence of vulnerabilities addressed by this Critical Security Patch Update."

How long does a WebLogic patch take to reach production at your company?

Sources

Spotted an error? Tell us. Every correction is logged on Standards.

Your reading room

Companies in this story

Our file on Oracle

  1. 20 SeptFiled later

    Oracle's data-centre lenders are stuck with $18 billion they cannot sell.

  2. 12 Sept

    Oracle raised its layoff budget by $700 million to $2.8 billion.

  3. 10 Sept

    An Oracle flaw let attackers take Social Security numbers. Bimbo Bakeries confirmed it.

  4. 9 Sept

    Brussels settled with SAP. It is now asking about Oracle.

  5. 8 Sept

    £19m budgeted. £216.5m lost.

All 6 Oracle stories

For your next steering committee

Questions for your own programme. They are not findings about any company in this story.

  1. 1Ask when systems of this kind in your landscape were last patched, and who confirms it.
  2. 2Ask which finance and ERP accounts can be reached from outside, and how each sign-in is protected.
  3. 3Ask how long a restore took the last time it was tested.

Issue 01 of the ERP LEADERS brief puts a timeline, the three-number review and six questions on one page. Read issue 01

Founding reader view is on in this browser. It is a reading view, not secure access. Print the working sheet

Founding reader

Welcome back. · Issue 01

1 comment under this story on LinkedIn. Read the discussion

Keep reading

The ERP LEADERS brief Get issue 01