securingyour.info

Icon

Question the integrity of your information

Vuln: Oracle patch 81 database security holes

Oracle have decided to follow suite with Microsoft on patch Tuesday with a staggering eighty one security patches to fix critical vulnerabilities in it’s database server software.  It is rumored that ten out of the tweleve health care organisations run oracle software so lets hope that they patch up fast. With some of the vulnerabilities as serious as remote exploitation with out the need for authentication lets hope the all the blue chips patch as soon as possible, especially the Sun worshipers as thirty one of the eighty one are for Oracle Sun products.

According to the pre-release statement by Oracle the following products and effected:

Oracle Database 11g Release 2, version 11.2.0.1

Oracle Database 11g Release 1, version 11.1.0.7

Oracle Database 10g Release 2, versions 10.2.0.3 and 10.2.0.4

Oracle Database 10g, Release 1, version 10.1.0.5

Oracle Fusion Middleware, 11gR1, versions 11.1.1.1.0 and 11.1.1.2.0

Oracle Application Server, 10gR3, version 10.1.3.5.0

Oracle Application Server, 10gR2, version 10.1.2.3.0

Oracle BI Publisher, versions 10.1.3.3.2, 10.1.3.4.0 and 10.1.3.4.1

Oracle Identity Management 10g, versions 10.1.4.0.1 and 10.1.4.3

Oracle E-Business Suite Release 12, versions 12.0.4, 12.0.5, 12.0.6, 12.1.1 and 12.1.2

Oracle E-Business Suite Release 11i, versions 11.5.10 and 11.5.10.2

Agile PLM, version 9.3.0.0

Oracle Transportation Management, versions 5.5, 6.0, and 6.1

PeopleSoft Enterprise CRM, FMS, HCM and SCM (Supply Chain), versions 8.9, 9.0 and 9.1

PeopleSoft Enterprise EPM, Campus Solutions, versions 8.9 and 9.0

PeopleSoft Enterprise PeopleTools, versions 8.49 and 8.50

Siebel Core, versions 7.7, 7.8, 8.0 and 8.1

Primavera P6 Enterprise Project Portfolio Management, versions 6.21.3.0 and 7.0.1.0

Oracle Sun Product Suite

Peoplesoft Enterprise CRM

Peoplesoft Enterprise EPM

Solaris

Open Solaris

Again do patch up and make sure you read the pre-release statement for more information

Vuln: 49 vulnerabilities will mark the largest ever batch of patches issued by Microsoft

Here we go again, patch Tuesday.  Microsoft will today release the patches for forty nine vulnerabilities and release sixteen bulletins four of which are marked as “Critical” the highest rating they can get. According to the Microsoft’s advanced notice a “Critical” rating is one that would allow the spread of internet worms without user action, to be honest anything that could compromise your organisations data and integrity is critical something they yet to understand. What has caused this sudden and rather large patch rush, you guessed it mostly to plug the holes used by the Stuxnet worm that targeted various key services and companies. Why you would run something like a Nuclear Power Plant or any country critical service on Microsoft is besides me really, its the equivalent of alarming your company or house then leaving the proverbial post-it note with the code on the front door. Nothing against Microsoft per se it has it’s place and time in any environment just not the most critical not until it far more secure and bug free than it is.

The products that are effected are listed below (basically everything):

Windows XP : Bulletins 1, 2, 3, 4, 6, 7,10, 11, 12, 13, 14, 15, 16

Windows Vista : Bulletins 1, 2, 3, 4, 6, 7,10, 11, 12, 13, 14, 15, 16

Windows 7 : Bulletins 1, 2, 3, 4, 6, 7,10, 11, 12, 13, 14, 15, 16

Windows XP : Bulletins 1, 2, 3, 4, 6, 7,10, 11, 12, 13, 14, 15, 16

Windows Server 2003 : Bulletins 1, 2, 3, 4, 6, 7,10, 11, 12, 13, 14, 15, 16

Windows Server 2008 : Bulletins 1, 2, 3, 4, 6, 7,10, 11, 12, 13, 14, 15, 16

Windows Server 2008 R2 : Bulletins 1, 2, 3, 4, 6, 7,10, 11, 12, 13, 14, 15, 16

Windows Sharepoint Services 3.0: Bulletins 5, 8

Microsoft Sharepoint Foundations 2010: Bulletins 5, 8

Microsoft Office Sharepoint Server 2007: Bulletins 5, 8

Microsoft Groove Server 2010: Bulletins 5, 8

Microsoft Office XP: Bulletins 8, 9

Microsoft Office 2003: Bulletins 8, 9

Microsoft Office 2007: Bulletins 8, 9

Microsoft Office 2010 32 bit: Bulletins 8, 9

Microsoft Office 2010 64bit: Bulletins 8, 9

Microsoft Office for Mac 2004: Bulletins 8, 9

Microsoft Office for Mac 2008: Bulletins 8, 9

Microsoft XML file converter: Bulletins 8, 9

Microsoft Word viewer: Bulletins 8, 9

Microsoft Excel viewer: Bulletins 8, 9

Microsoft Office Compatibility Pack: Bulletins 8, 9

Like I said just about everything, so do patch up there are some really serious holes being fixed and for that we can be grateful, even if it did take a potential nuclear disaster to make it happen.