
'You are really spoiling us... '
By Joris Evers
Published: 19 October 2005 08:50 BST
Oracle on Tuesday released fixes for a laundry list of security vulnerabilities in many of its software products.
The "Critical Patch Update", part of Oracle's quarterly patch release cycle, delivers fixes for 33 flaws in Oracle's Database products, 14 in its Application Server, 13 in the Collaboration Suite, 22 in E-Business Suite and Applications, four in PeopleSoft's PeopleTools, and two in JD Edwards software.
Several of the flaws carry Oracle's most serious rating, which means they are easy to exploit and an attack can have a wide impact, according to the alert. Symantec said in an alert to users of its DeepSight intelligence service: "The most severe of the vulnerabilities could possibly expose affected computers to complete compromise."
Oracle doesn't provide many details in its advisory, which could be a challenge for users when prioritising patches, Pete Finnigan, a security specialist, wrote on his blog. "The descriptions for all the bugs except for the database section give nothing away whatsoever," he said.
Oracle has been criticised for dragging its heels on fixing security flaws and being unresponsive to researchers who find bugs. In response, Oracle's chief security officer, Mary Ann Davidson, said security researchers can be a problem when it comes to product security.
Joris Evers writes for CNET News.com
Provide 2nd level infrastructure support as required - Undertake the diagnosis and completion of Root Cause Analyses to enable Problem Management as ...
Trouble shoot and fix technical problems, liaising with product management and technical support to organise a patch if necessary. Understand and be ...
The role is to provide day to day support, troubleshooting, tuning, administration, systems hardening (security), and project work for a wide range ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...