Oracle follows Microsoft with major security patches
The enterprise software giant releases a big package of security fixes for the last time this year.

Enterprise software company Oracle has released a Patch Tuesday' style major security update for 20 product versions.
Coming hot on the heels of the Microsoft patches, the Oracle Critical Patch Update fixes multiple security vulnerabilities. Oracle said that due to the threat posed by successful attacks, customers should apply fixes as soon as possible.
Included in the update are 15 new security fixes for the Oracle Database Suite and six for the Application Server Suite, with some vulnerabilities remotely exploitable over a network without the need for a user name and password.
Other products affected were Oracle Collaboration Suite, E-business Suite and Applications, Enterprise Manager, PeopleSoft Enterprise and JD Edwards Enterprise One, Siebel Enterprise, and WebLogic Server and Workshop.
The most serious flaw was with the WebLogic Server Plugins for Apache component with scored a 10 - the highest level on the severity scale.
Until the fixes were applied Oracle said that there were workarounds which could be used as a short-term solution: "It may be possible to reduce the risk of successful attack by restricting network protocols required by an attack."
It continued: "For attacks that require certain privileges or access to certain packages, removing the privileges or the ability to access the packages from unprivileged users may reduce the risk of successful attack."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
However Oracle warned that this could break application functionality, and that neither should be considered a long-term solution as they wouldn't correct the underlying problem.
-
More than half of UK enterprises regret at least one software purchase – here’s how to prevent buyer’s remorse
News More than half of UK enterprises regret at least one software purchase they've made in the last 18 months.
-
Zellis snaps up AI-powered HR software firm elementsuite
News Elementsuite will be integrated with Zellis’ own payroll and HR software offering
-
‘SaaS dependency’ is becoming a major issue for tech leaders
News The survey highlighted issues around maintenance, innovation, and data
-
Organizations shift away from Oracle Java as pricing changes bite
News A survey from Azul Systems finds that, along with cost, customers cite a preference for open source and the threat of a Java usage audit
-
Why Java 17 growth is ‘exploding’
News Java 17 is now the most popular LTS version, according to application data from New Relic, but what's driving this growth?
-
Monday.com review: Work management platform works best when you pay for it
Reviews The versatile 'Work OS' skilfully balances power, flexibility, and ease of use
-
SuiteWorld 2023: NetSuite's day-two announcements
Live Blog Keep up-to-date with all the day-two announcements from NetSuite SuiteWorld 2023
-
Can Oracle really be Linux's knight in shining armor?
Opinion The self-proclaimed champion of open source freedom would like you to forget about its history