Summary of the content of the October 2016 Critical Patch UpdateThe October 2016 Critical Patch Update was released on October 18, 2016. It provides fixes for 253 security vulnerabilities across a wide range of product families including: Oracle Database Server, Oracle Secure Backup, Oracle Fusion Middleware, Oracle Enterprise Manager, Oracle E-Business Suite, Oracle Supply Chain Products Suite, Oracle PeopleSoft, Oracle JDEdwards, Oracle Siebel CRM, Oracle Industry Applications (Communications, Financial Services, Health Sciences, Hospitality, Insurance, and Retail), Oracle Primavera, Oracle Java SE, Oracle Sun Products Suite, Oracle Linux and Virtualization, and Oracle MySQL. 83 of these 253 new security fixes are for third-party components (e.g., open source components) in use with these Oracle product distributions. It is likely that future Critical Patch Update releases will continue to include a number of fixes for third-party components used by Oracle products. This is due in part to the growing attention widely-used components are getting from the security community, which should result in overall improvements in the secure development practices of many open source projects.Out of these 253 new security fixes, 9 are for the Oracle Database. 1 of these Database vulnerabilities is remotely exploitable without authentication. 1 of these fixes is applicable for Database client deployments. The maximum CVSS Base Score reported for these database vulnerabilities is 9.1. Oracle Fusion Middleware receives 29 new security fixes. 19 of these vulnerabilities are remotely exploitable without authentication, and the maximum CVSS Base Score reported for these Fusion Middleware vulnerabilities is 9.8.Oracle Enterprise Manager receives 5 new security fixes, 4 of which are fore remotely exploitable without authentication bugs. The maximum CVSS Base Score reported for these Enterprise Manager vulnerabilities is 8.2.The October 2016 Critical Patch Update provides a large number of fixes for Oracle applications, including E-Business Suite (21), Supply Chain Products Suite (19), PeopleSoft (11), JDEdwards(2), Siebel CRM (3), and Commerce (7). As a reminder, applications deployments are likely to include Oracle Database and Fusion Middleware components that are affected by vulnerabilities fixed in this Critical Patch Update. These Database and Fusion Middleware vulnerabilities are not listed in the risk matrices for Oracle applications, and Oracle applications customers should refer to the Database and Fusion Middleware risk matrices to determine the applicability of these fixes in their applications deployment. In other words, it is important to “patch across the stack” in order to maintain a good security posture, as the patching of vulnerabilities at one layer of the stack cannot prevent the exploitation of vulnerabilities in other parts of the technology stack.The October 2016 Critical Patch Update also provides a number of fixes for industry-specific applications: Communication (36), Financial (24), Health Sciences (1), Hospitality (3), Insurance (1), and Retail (10).Finally, the October 2016 Critical Patch Update includes 7 new fixes for Java SE. All of these vulnerabilities apply only to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. They not apply to Java deployments, typically in servers, which load and run only trusted code (e.g., code installed by an administrator).
đang được dịch, vui lòng đợi..
