Categories: SecurityWorkspace

Oracle Patches 89 Vulnerabilities In Sizeable Update

Oracle has released a sizeable Critical Patch Update with 89 flaws fixed, almost half of which could have allowed for remote access of machines.

More than 40 percent of flaws addressed allow for remote access, with the Oracle database having four such vulnerabilities.

Oracle’s MySQL database has 18 vulnerabilities covered, two of which are remotely accessible. There are  16 fixes for products in the Oracle Sun line, eight of which could lead to remote exploitation.

Many Oracle flaws

Fusion Middleware was riddled with flaws two, with 21 vulnerabilities, 16 of which can be exploited by external malicious hackers.

A total of 18 different researchers were credited for helping find flaws and onlookers are getting concerned at the high number of security holes appearing in Oracle products.

“The constant drumbeat of critical Oracle patches is more than a little alarming particularly because the vulnerabilities are frequently reported by 3rd parties who presumably do not have access to full source code,” said Craig Young, security researcher at Tripwire.

“It’s also noteworthy that there every Oracle CPU release this year has plugged dozens of vulnerabilities.

“By my count, Oracle has already acknowledged and fixed 343 security issues in 2013.  In case there was any doubt, this should be a big red flag to end users that Oracle’s security practices are simply not working.”

You can find Oracle’s update in full here.

What do you know about Internet security? Find out with our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Tesla Backs Away From Gigacasting Manufacturing – Report

Tesla retreats from pioneering gigacasting manufacturing process, amid cost cutting and challenges at EV giant

3 hours ago

US Urges No AI Control Of Nuclear Weapons

No skynet please. After the US, UK and France pledge human only control of nuclear…

4 hours ago

LastPass Separates From Parent After Security Incidents

New chapter for LastPass as it becomes an independent company to focus on cybersecurity, after…

7 hours ago

US To Ban Huawei, ZTE From Certifying Wireless Kit

US FCC seeks to ban Chinese telecom firms at centre of national security concerns from…

11 hours ago

Anthropic Launches Enterprise-Focused Claude, Plus iPhone App

Two updates to Anthropic's AI chatbot Claude sees arrival of a new business-focused plan, as…

12 hours ago