US-CERT Technical Cyber Security Alert TA09-015A -- Oracle Updates for Multiple Vulnerabilities
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
National Cyber Alert System
Technical Cyber Security Alert TA09-015A
Oracle Updates for Multiple Vulnerabilities
Original release date: January 15, 2009
Last revised: --
Source: US-CERT
Systems Affected
* Oracle Database 11g, version 11.1.0.6
* Oracle Database 10g Release 2, versions 10.2.0.2, 10.2.0.3, and
10.2.0.4
* Oracle Database 10g, version 10.1.0.5
* Oracle Database 9i Release 2, versions 9.2.0.8 and 9.2.0.8DV
* Oracle Secure Backup, versions 10.1.0.1, 10.1.0.2, 10.1.0.3,
10.2.0.2, and 10.2.0.3
* Oracle TimesTen In-Memory Database, versions 7.0.5.1.0,
7.0.5.2.0, 7.0.5.3.0, and 7.0.5.4.0
* Oracle Application Server 10g Release 3 (10.1.3), version
10.1.3.3.0
* Oracle Application Server 10g Release 2 (10.1.2), versions
10.1.2.2.0 and 10.1.2.3.0
* Oracle Collaboration Suite 10g, version 10.1.2
* Oracle E-Business Suite Release 12, version 12.0.6
* Oracle E-Business Suite Release 11i, version 11.5.10.2
* Oracle Enterprise Manager Grid Control 10g Release 4, version
10.2.0.4
* PeopleSoft Enterprise HRMS, versions 8.9 and 9.0
* JD Edwards Tools, version 8.97
* Oracle WebLogic Server (formerly BEA WebLogic Server) 10.0
released through MP1, 10.3 GA
* Oracle WebLogic Server (formerly BEA WebLogic Server) 9.0 GA,
9.1 GA, 9.2 released through MP3
* Oracle WebLogic Server (formerly BEA WebLogic Server) 8.1
released through SP6
* Oracle WebLogic Server (formerly BEA WebLogic Server) 7.0
released through SP7
* Oracle WebLogic Portal (formerly BEA WebLogic Portal) 10.0
released through MP1, 10.2 GA, 10.3 GA
* Oracle WebLogic Portal (formerly BEA WebLogic Portal) 9.2
released through MP3
* Oracle WebLogic Portal (formerly BEA WebLogic Portal) 8.1
released through SP6
For more information regarding affected product versions, please
see the Oracle Critical Patch Update - January 2009.
Overview
Oracle products and components are affected by multiple
vulnerabilities. The impacts of these vulnerabilities include
remote execution of arbitrary code, information disclosure, and
denial of service.
I. Description
The Oracle Critical Patch Update - January 2009 addresses 41
vulnerabilities in different Oracle products and components. The
document provides information about affected components, access and
authorization required, and the impact from the vulnerabilities on
data confidentiality, integrity, and availability.
Oracle has associated CVE identifiers with the vulnerabilities
addressed in this Critical Patch Update. If significant additional
details about vulnerabilities and remediation techniques become
available, we will update the Vulnerability Notes Database.
II. Impact
The impact of these vulnerabilities varies depending on the
product, component, and configuration of the system. Potential
consequences include the execution of arbitrary code or commands,
information disclosure, and denial of service. Vulnerable
components may be available to unauthenticated, remote attackers.
An attacker who compromises an Oracle database may be able to
access sensitive information.
III. Solution
Apply the appropriate patches or upgrade as specified in the Oracle
Critical Patch Update - January 2009. Note that this document only
lists newly corrected issues. Updates to patches for previously
known issues are not listed.
IV. References
* Oracle Critical Patch Update for January 2009 -
<http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2009.html>
* Critical Patch Updates and Security Alerts -
<http://www.oracle.com/technology/deploy/security/alerts.htm>
* Map of Public Vulnerability to Advisory/Alert -
<http://www.oracle.com/technology/deploy/security/pdf/public_vuln_to_advisory_mapping.html>
____________________________________________________________________
The most recent version of this document can be found at:
<http://www.us-cert.gov/cas/techalerts/TA09-015A.html>
____________________________________________________________________
Feedback can be directed to US-CERT Technical Staff. Please send
email to <cert@cert.org> with "TA09-015A Feedback VU#897316" in
the subject.
____________________________________________________________________
For instructions on subscribing to or unsubscribing from this
mailing list, visit <http://www.us-cert.gov/cas/signup.html>.
____________________________________________________________________
Produced 2009 by US-CERT, a government organization.
Terms of use:
<http://www.us-cert.gov/legal.html>
____________________________________________________________________
Revision History
January 15, 2009: Initial release
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)
iQEVAwUBSW+R2HIHljM+H4irAQLnswf/f0DIMhNOZ/sC88dH+pCeSXEDMl7/HZtL
MJEzLABKMeWElPFiA3QY5EVGUEd6CJvdPq9aA2F0f85On+nm6+7SPV2uwc8xl+KM
QEkAOc2jS7fvw7QOXbrUo0kgTg8Z4vyR8km6OpCNOIHopCZ2KDwwSEg31UaOCKW1
JumHsB0unwEKoR3s8/OvWUkKgnWuhz4AtrYFZjzSCxrC+S2sB0gukW+z8RffNRgF
82MijTz62S3I9dcV4ssuBXldBMqeGfY40HxduQjoDBrBdmBuWb5+pEeMd3GblJet
mxgqACcMLIzozfJZczejK4m+K41RZd1nbEK/rpMCsdr9y+a7qFmM9g==
=Wkfo
-----END PGP SIGNATURE-----
13 comments:
I constantly spent my half an hour to read this weblog's content all the time along with a cup of coffee.
My web blog; website
It's going to be ending of mine day, however before end I am reading this wonderful piece of writing to increase my know-how. http://www.tinnitus411.com/stop-ringing-in-the-ears/
Also see my webpage > http://www.tinnitus411.com/stop-ringing-in-the-ears/
I've been exploring for a little for any high quality articles or blog posts on this sort of space . Exploring in Yahoo I finally stumbled upon this web site. Studying this information So i'm glаԁ to show that I've a very good uncanny feeling I found out exactly what I needed. I such a lot surely will make sure to do not put out of your mind this web site and provides it a look regularly. simply click the up coming site
Very soon thiѕ web page will be famous among all blog users,
duе to it's pleasant content Www.Tinnitus411.com
Also see my web site :: Www.Tinnitus411.com
Keep working ,great job!
Also visit my webpage ... http://www.facenetz.com
We stumbled ovег here coming from a diffеrent website and thought
I should check things οut. I like whаt
I see so noω i'm following you. Look forward to looking at your web page again. Knowing How To Cure Tinnitus - Can Stop You Losing Your Hearing
Itѕ not my first time to pay a quick vіsit this web site, і аm browsing thіs
wеb site ԁailly аnԁ obtain good infoгmation from herе everуԁау.
keep reading
Highly descriрtіvе blog, I liked that a lot.
Will therе bе a part 2? Recommended Website
ӏ am reallу enjoying the thеme/design of your web site.
Do уou eveг run іnto any inteгnet brоwseг
compаtibility isѕues? A numbеr of my
blog reaԁers have comρlaineԁ аbout
my blog not wοrking correctly in Exрloгer but looks gгeat іn Chrome.
Dо you hаvе any solutionѕ to help fix thiѕ pгοblem?
visit the next website page
my page: visit the next website page
ӏt's impressive that you are getting thoughts from this piece of writing as well as from our dialogue made at this time. More hints
There іs definately а great deal to leаrn about this
topіc. I really like all of the points you maԁe.
mouse click the next page
Ηi thеre! Thіs іs mу fіrst visit tο youг blog!
We аre а group of volunteers аnd starting a new ρroϳect in a community in thе same niсhe.
Your blog prοvided us useful іnformation tο worκ on.
You have done a maгvellous job! www.bacterialvaginosisremedies.com/treat-bacterial-vaginosis/
Hеy thеre I am so gгateful I found your weblog,
ӏ геallу fоund you by
miѕtaκе, whilе І wаѕ гeseаrching on Yahоo fοr something elsе, Anyhow ӏ am hегe now anԁ wοuld just
like to say thanks а lot for a tremendouѕ post and a
аll гοund еntertаіning blog (I also love thе theme/ԁesіgn), I don�t have timе to геaԁ it all at the moment but I have bοoκmaгked it anԁ
also аdded in your RSS feeԁs, so when I have tіme
Ӏ ωill be bacκ tο гead a gгeat dеal more, Ρlease dо keep up the ехсellent jo.
visit the following page
Post a Comment