Oracle follows Microsoft with major security patches
The enterprise software giant releases a big package of security fixes for the last time this year.

Enterprise software company Oracle has released a Patch Tuesday' style major security update for 20 product versions.
Coming hot on the heels of the Microsoft patches, the Oracle Critical Patch Update fixes multiple security vulnerabilities. Oracle said that due to the threat posed by successful attacks, customers should apply fixes as soon as possible.
Included in the update are 15 new security fixes for the Oracle Database Suite and six for the Application Server Suite, with some vulnerabilities remotely exploitable over a network without the need for a user name and password.
Other products affected were Oracle Collaboration Suite, E-business Suite and Applications, Enterprise Manager, PeopleSoft Enterprise and JD Edwards Enterprise One, Siebel Enterprise, and WebLogic Server and Workshop.
The most serious flaw was with the WebLogic Server Plugins for Apache component with scored a 10 - the highest level on the severity scale.
Until the fixes were applied Oracle said that there were workarounds which could be used as a short-term solution: "It may be possible to reduce the risk of successful attack by restricting network protocols required by an attack."
It continued: "For attacks that require certain privileges or access to certain packages, removing the privileges or the ability to access the packages from unprivileged users may reduce the risk of successful attack."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
However Oracle warned that this could break application functionality, and that neither should be considered a long-term solution as they wouldn't correct the underlying problem.
-
Blackouts in Spain and Portugal could be a cyber attack
Both countries are "paralyzed" by nationwide power outages
By Jane McCallion
-
Cisco takes aim at AI security at RSAC with ServiceNow partnership
News The companies claim Cisco AI Defense and ServiceNow SecOps will help address new challenges raised by AI
By Jane McCallion
-
More than half of UK enterprises regret at least one software purchase – here’s how to prevent buyer’s remorse
News More than half of UK enterprises regret at least one software purchase they've made in the last 18 months.
By Emma Woollacott
-
Zellis snaps up AI-powered HR software firm elementsuite
News Elementsuite will be integrated with Zellis’ own payroll and HR software offering
By Daniel Todd
-
‘SaaS dependency’ is becoming a major issue for tech leaders
News The survey highlighted issues around maintenance, innovation, and data
By Emma Woollacott
-
Organizations shift away from Oracle Java as pricing changes bite
News A survey from Azul Systems finds that, along with cost, customers cite a preference for open source and the threat of a Java usage audit
By Emma Woollacott
-
Why Java 17 growth is ‘exploding’
News Java 17 is now the most popular LTS version, according to application data from New Relic, but what's driving this growth?
By Steve Ranger
-
Monday.com review: Work management platform works best when you pay for it
Reviews The versatile 'Work OS' skilfully balances power, flexibility, and ease of use
By Nik Rawlinson
-
SuiteWorld 2023: NetSuite's day-two announcements
Live Blog Keep up-to-date with all the day-two announcements from NetSuite SuiteWorld 2023
By Rory Bathgate
-
Can Oracle really be Linux's knight in shining armor?
Opinion The self-proclaimed champion of open source freedom would like you to forget about its history
By Richard Speed