Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

10/17/2018
05:25 PM
50%
50%

Oracle Issues Massive Collection of Critical Security Updates

The software updates from Oracle address a record number of vulnerabilities.

Updated: 10/18/2018 to correct Onapsis blog information.

Oracle this week issued a Critical Patch Update (CPU) encompassing 301 separate updates spread across the entire Oracle family of products. While not every update is marked "critical," in all they represent a variety of vulnerabilities that Oracle recommends all customers patch as quickly as possible.

According to Onapsis, this marks one of the largest number of vulnerabilities in an Oracle CPU. In its analysis of the CPU, Onapsis says that 28 flaws share the highest-level criticality score — 9.8 — from the Common Vulnerability Scoring System (CVSS) and that more than half of the vulnerabilities lie in business-critical applications.

Waratek issued a guidance statement focusing on programming capabilties, noting that "One-third of the 12 new Java SE bugs carry a severity rating of high or critical; 11 of the 12 can be remotely exploited. Eight of the 12 new WebLogic vulnerabilities are critical."

For more, read here, here, and here.

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ThomasMaloney
50%
50%
ThomasMaloney,
User Rank: Apprentice
12/21/2018 | 4:00:25 AM
Do not take the risk
Some users are to complacent when it comes to system updates. Since these updates often take a lot of time to complete, users become reluctant to complete them. This opens up the opportunity for their systems to be come vulnerable and they are letting themselves become exposed to threats.
markgrogan
50%
50%
markgrogan,
User Rank: Apprentice
12/18/2018 | 10:13:58 PM
Fix and Patch
I wonder if it's a better idea to release the patches or just blast them all out at one shot so that people can download all the fixes at one shot. It makes for  a shorter down time I reckon? But honestly, the amount of patches that are being released by Oracle right now, it sort of puts a bit of a dampener if you think about just how secure your system has been... Well.. At least they are doing something about it and fixing it and letting their users know I suppose! 
KellimWorthington
50%
50%
KellimWorthington,
User Rank: Apprentice
11/29/2018 | 12:47:53 AM
update
i didn't know much detail about this issues in oracle i am new database this i didn't have much knowledge this is why i don't know what is the issue if anyone full then tells me about this because i wanted to do my university assignment for me on any topic related to database and its features.
US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
MITRE Releases 2019 List of Top 25 Software Weaknesses
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2019
Preventing PTSD and Burnout for Cybersecurity Professionals
Craig Hinkley, CEO, WhiteHat Security,  9/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-14994
PUBLISHED: 2019-09-19
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version 4.1.3, from version 4.2.0 before version 4.2.5, from version 4.3.0 before version 4.3.4, and version...
CVE-2019-15000
PUBLISHED: 2019-09-19
The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0 before 6.1.8 (the fixed version for 6.1.x), from 6.2.0 before 6.2.6 (the fixed version for 6.2.x), from 6.3.0 before 6....
CVE-2019-15001
PUBLISHED: 2019-09-19
The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.1.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote attackers with Administrator permissions to gain rem...
CVE-2019-16398
PUBLISHED: 2019-09-19
On Keeper K5 20.1.0.25 and 20.1.0.63 devices, remote code execution can occur by inserting an SD card containing a file named zskj_script_run.sh that executes a reverse shell.
CVE-2019-11779
PUBLISHED: 2019-09-19
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.