Thursday, January 15, 2009

US-CERT Technical Cyber Security Alert TA09-015A -- Oracle Updates for Multiple Vulnerabilities

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


National Cyber Alert System

Technical Cyber Security Alert TA09-015A


Oracle Updates for Multiple Vulnerabilities

Original release date: January 15, 2009
Last revised: --
Source: US-CERT


Systems Affected

* Oracle Database 11g, version 11.1.0.6
* Oracle Database 10g Release 2, versions 10.2.0.2, 10.2.0.3, and
10.2.0.4
* Oracle Database 10g, version 10.1.0.5
* Oracle Database 9i Release 2, versions 9.2.0.8 and 9.2.0.8DV
* Oracle Secure Backup, versions 10.1.0.1, 10.1.0.2, 10.1.0.3,
10.2.0.2, and 10.2.0.3
* Oracle TimesTen In-Memory Database, versions 7.0.5.1.0,
7.0.5.2.0, 7.0.5.3.0, and 7.0.5.4.0
* Oracle Application Server 10g Release 3 (10.1.3), version
10.1.3.3.0
* Oracle Application Server 10g Release 2 (10.1.2), versions
10.1.2.2.0 and 10.1.2.3.0
* Oracle Collaboration Suite 10g, version 10.1.2
* Oracle E-Business Suite Release 12, version 12.0.6
* Oracle E-Business Suite Release 11i, version 11.5.10.2
* Oracle Enterprise Manager Grid Control 10g Release 4, version
10.2.0.4
* PeopleSoft Enterprise HRMS, versions 8.9 and 9.0
* JD Edwards Tools, version 8.97
* Oracle WebLogic Server (formerly BEA WebLogic Server) 10.0
released through MP1, 10.3 GA
* Oracle WebLogic Server (formerly BEA WebLogic Server) 9.0 GA,
9.1 GA, 9.2 released through MP3
* Oracle WebLogic Server (formerly BEA WebLogic Server) 8.1
released through SP6
* Oracle WebLogic Server (formerly BEA WebLogic Server) 7.0
released through SP7
* Oracle WebLogic Portal (formerly BEA WebLogic Portal) 10.0
released through MP1, 10.2 GA, 10.3 GA
* Oracle WebLogic Portal (formerly BEA WebLogic Portal) 9.2
released through MP3
* Oracle WebLogic Portal (formerly BEA WebLogic Portal) 8.1
released through SP6

For more information regarding affected product versions, please
see the Oracle Critical Patch Update - January 2009.


Overview

Oracle products and components are affected by multiple
vulnerabilities. The impacts of these vulnerabilities include
remote execution of arbitrary code, information disclosure, and
denial of service.


I. Description

The Oracle Critical Patch Update - January 2009 addresses 41
vulnerabilities in different Oracle products and components. The
document provides information about affected components, access and
authorization required, and the impact from the vulnerabilities on
data confidentiality, integrity, and availability.

Oracle has associated CVE identifiers with the vulnerabilities
addressed in this Critical Patch Update. If significant additional
details about vulnerabilities and remediation techniques become
available, we will update the Vulnerability Notes Database.


II. Impact

The impact of these vulnerabilities varies depending on the
product, component, and configuration of the system. Potential
consequences include the execution of arbitrary code or commands,
information disclosure, and denial of service. Vulnerable
components may be available to unauthenticated, remote attackers.
An attacker who compromises an Oracle database may be able to
access sensitive information.


III. Solution

Apply the appropriate patches or upgrade as specified in the Oracle
Critical Patch Update - January 2009. Note that this document only
lists newly corrected issues. Updates to patches for previously
known issues are not listed.


IV. References

* Oracle Critical Patch Update for January 2009 -
<http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2009.html>

* Critical Patch Updates and Security Alerts -
<http://www.oracle.com/technology/deploy/security/alerts.htm>

* Map of Public Vulnerability to Advisory/Alert -
<http://www.oracle.com/technology/deploy/security/pdf/public_vuln_to_advisory_mapping.html>

____________________________________________________________________

The most recent version of this document can be found at:

<http://www.us-cert.gov/cas/techalerts/TA09-015A.html>
____________________________________________________________________

Feedback can be directed to US-CERT Technical Staff. Please send
email to <cert@cert.org> with "TA09-015A Feedback VU#897316" in
the subject.
____________________________________________________________________

For instructions on subscribing to or unsubscribing from this
mailing list, visit <http://www.us-cert.gov/cas/signup.html>.
____________________________________________________________________

Produced 2009 by US-CERT, a government organization.

Terms of use:

<http://www.us-cert.gov/legal.html>
____________________________________________________________________

Revision History

January 15, 2009: Initial release


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iQEVAwUBSW+R2HIHljM+H4irAQLnswf/f0DIMhNOZ/sC88dH+pCeSXEDMl7/HZtL
MJEzLABKMeWElPFiA3QY5EVGUEd6CJvdPq9aA2F0f85On+nm6+7SPV2uwc8xl+KM
QEkAOc2jS7fvw7QOXbrUo0kgTg8Z4vyR8km6OpCNOIHopCZ2KDwwSEg31UaOCKW1
JumHsB0unwEKoR3s8/OvWUkKgnWuhz4AtrYFZjzSCxrC+S2sB0gukW+z8RffNRgF
82MijTz62S3I9dcV4ssuBXldBMqeGfY40HxduQjoDBrBdmBuWb5+pEeMd3GblJet
mxgqACcMLIzozfJZczejK4m+K41RZd1nbEK/rpMCsdr9y+a7qFmM9g==
=Wkfo
-----END PGP SIGNATURE-----

13 comments:

Anonymous said...

I constantly spent my half an hour to read this weblog's content all the time along with a cup of coffee.

My web blog; website

Anonymous said...

It's going to be ending of mine day, however before end I am reading this wonderful piece of writing to increase my know-how. http://www.tinnitus411.com/stop-ringing-in-the-ears/
Also see my webpage > http://www.tinnitus411.com/stop-ringing-in-the-ears/

Anonymous said...

I've been exploring for a little for any high quality articles or blog posts on this sort of space . Exploring in Yahoo I finally stumbled upon this web site. Studying this information So i'm glаԁ to show that I've a very good uncanny feeling I found out exactly what I needed. I such a lot surely will make sure to do not put out of your mind this web site and provides it a look regularly. simply click the up coming site

Anonymous said...

Very soon thiѕ web page will be famous among all blog users,
duе to it's pleasant content Www.Tinnitus411.com
Also see my web site :: Www.Tinnitus411.com

Anonymous said...

Keep working ,great job!

Also visit my webpage ... http://www.facenetz.com

Anonymous said...

We stumbled ovег here coming from a diffеrent website and thought
I should check things οut. I like whаt
I see so noω i'm following you. Look forward to looking at your web page again. Knowing How To Cure Tinnitus - Can Stop You Losing Your Hearing

Anonymous said...

Itѕ not my first time to pay a quick vіsit this web site, і аm browsing thіs
wеb site ԁailly аnԁ obtain good infoгmation from herе everуԁау.
keep reading

Anonymous said...

Highly descriрtіvе blog, I liked that a lot.
Will therе bе a part 2? Recommended Website

Anonymous said...

ӏ am reallу enjoying the thеme/design of your web site.

Do уou eveг run іnto any inteгnet brоwseг
compаtibility isѕues? A numbеr of my
blog reaԁers have comρlaineԁ аbout
my blog not wοrking correctly in Exрloгer but looks gгeat іn Chrome.

Dо you hаvе any solutionѕ to help fix thiѕ pгοblem?
visit the next website page
my page: visit the next website page

Anonymous said...

ӏt's impressive that you are getting thoughts from this piece of writing as well as from our dialogue made at this time. More hints

Anonymous said...

There іs definately а great deal to leаrn about this
topіc. I really like all of the points you maԁe.
mouse click the next page

Anonymous said...

Ηi thеre! Thіs іs mу fіrst visit tο youг blog!
We аre а group of volunteers аnd starting a new ρroϳect in a community in thе same niсhe.
Your blog prοvided us useful іnformation tο worκ on.
You have done a maгvellous job! www.bacterialvaginosisremedies.com/treat-bacterial-vaginosis/

Anonymous said...

Hеy thеre I am so gгateful I found your weblog,
ӏ геallу fоund you by
miѕtaκе, whilе І wаѕ гeseаrching on Yahоo fοr something elsе, Anyhow ӏ am hегe now anԁ wοuld just
like to say thanks а lot for a tremendouѕ post and a
аll гοund еntertаіning blog (I also love thе theme/ԁesіgn), I don�t have timе to геaԁ it all at the moment but I have bοoκmaгked it anԁ
also аdded in your RSS feeԁs, so when I have tіme
Ӏ ωill be bacκ tο гead a gгeat dеal more, Ρlease dо keep up the ехсellent jo.
visit the following page

CNN.com

News: Breaking News -- MercuryNews.com

AP Top U.S. News At 8:45 p.m.