The software updates from Oracle address a record number of vulnerabilities.
Updated: 10/18/2018 to correct Onapsis blog information.
Oracle this week issued a Critical Patch Update (CPU) encompassing 301 separate updates spread across the entire Oracle family of products. While not every update is marked "critical," in all they represent a variety of vulnerabilities that Oracle recommends all customers patch as quickly as possible.
According to Onapsis, this marks one of the largest number of vulnerabilities in an Oracle CPU. In its analysis of the CPU, Onapsis says that 28 flaws share the highest-level criticality score — 9.8 — from the Common Vulnerability Scoring System (CVSS) and that more than half of the vulnerabilities lie in business-critical applications.
Waratek issued a guidance statement focusing on programming capabilties, noting that "One-third of the 12 new Java SE bugs carry a severity rating of high or critical; 11 of the 12 can be remotely exploited. Eight of the 12 new WebLogic vulnerabilities are critical."
For more, read here, here, and here.
Black Hat Europe returns to London Dec 3-6 2018 with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.
About the Author(s)
You May Also Like
The fuel in the new AI race: Data
April 23, 2024Securing Code in the Age of AI
April 24, 2024Beyond Spam Filters and Firewalls: Preventing Business Email Compromises in the Modern Enterprise
April 30, 2024Key Findings from the State of AppSec Report 2024
May 7, 2024Is AI Identifying Threats to Your Network?
May 14, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024