Oracle recently released it’s January 2015 Critical Patch Update that includes 169 new security fixes across the following product groups:
- Oracle Database
- Oracle Fusion Middleware
- Oracle Fusion Applications
- Oracle Enterprise Manager
- Oracle Applications – E-Business Suite
- Oracle Applications – Oracle Supply Chain, PeopleSoft Enterprise, JD Edwards Product Suite, Siebel and iLearning
- Oracle Communications Industry Suite
- Oracle Retail Industry Suite
- Oracle Health Sciences Industry Suite
- Oracle Java SE
- Oracle and Sun Systems Products Suite
- Oracle Linux and Virtualization Products
- Oracle MySQL
None of these database vulnerabilities are remotely exploitable without authentication, but a number of them include severe vulnerabilities.
Oracle highly recommends implementing this critical patch as soon as possible.
Oracle has received specific reports of malicious exploitation of vulnerabilities for which Oracle has already released fixes. In some instances, it has been reported that malicious attackers have been successful because customers had failed to apply these Oracle patches. Oracle therefore strongly recommends that customers remain on actively-supported versions and apply Critical Patch Update fixes without delay.