Mailing List

Name:

Email:

[SingCERT] Oracle Critical Patch Update Advisory - April 2011

Attention: open in a new window. PDFPrintE-mail

[ Summary ]

Oracle has released Critical Patch Update advisory for April 2011. This Critical Patch Update contains 73 new security vulnerability fixes across hundreds of Oracle products. Some of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password.  Due to the threat posed by a successful attack, it is strongly recommends that users apply Critical Patch Update fixes as soon as possible.

 

[ Affected Systems ]

Security vulnerabilities addressed by this Critical Patch Update affect the following products:

 

Oracle Database 11g Release 2, versions 11.2.0.1, 11.2.0.2

Oracle Database 11g Release 1, version 11.1.0.7

Oracle Database 10g Release 2, versions 10.2.0.3, 10.2.0.4, 10.2.0.5

Oracle Database 10g Release 1, version 10.1.0.5

Oracle Fusion Middleware 11g Release 1, versions 11.1.1.2.0, 11.1.1.3.0, 11.1.1.4.0

Oracle Application Server 10g Release 3, version 10.1.3.5.0

Oracle Application Server 10g Release 2, version 10.1.2.3.0

Oracle Identity Management 10g, versions 10.1.4.0.1, 10.1.4.3

Oracle JRockit, versions R27.6.8 and earlier (JDK/JRE 1.4.2, 5, 6), R28.1.1 and earlier (JDK/JRE 5, 6)

Oracle Outside In Technology, versions 8.3.2.0, 8.3.5.0

Oracle WebLogic Server, versions 8.1.6, 9.2.3, 9.2.4, 10.0.2, 11gR1 (10.3.2, 10.3.3, 10.3.4)

Oracle E-Business Suite Release 12, versions 12.0.6, 12.1.1, 12.1.2, 12.1.3

Oracle E-Business Suite Release 11i, version 11.5.10.2

Oracle Agile Technology Platform, versions 9.3.0.2, 9.3.1

Oracle PeopleSoft Enterprise CRM, version 8.9

Oracle PeopleSoft Enterprise ELS, versions 9.0, 9.1

Oracle PeopleSoft Enterprise HRMS, versions 9.0, 9.1

Oracle PeopleSoft Enterprise Portal, versions 8.8, 8.9, 9.0, 9.1

Oracle PeopleSoft Enterprise People Tools, versions 8.49, 8.50, 8.51

Oracle JD Edwards OneWorld Tools, version 24.1.x

Oracle JD Edwards EnterpriseOne Tools, version 8.98.x

Oracle Siebel CRM Core, versions 7.8.2, 8.0.0, 8.1.1

Oracle InForm, versions 4.5, 4.6, 5.0

Oracle Sun Product Suite

Oracle Open Office, version 3 and StarOffice/StarSuite, versions 7, 8

 

[ Solution/Workaround ]

Review the Oracle Critical Patch Update Advisory and apply the fixes as soon as possible.

 

[ Reference ]

http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html