Personal tools
You are here: Home Oracle Security Blog Archive 2009 April

Entries For: April 2009

April 29, 2009

Integrigy at COLLABORATE 09

For those of you not familiar with COLLABORATE or have not previously attended, the Oracle Applications Users Group (OAUG), Independent Oracle Users Group (IOUG), and Quest have teamed together to host a user-driven event with exceptional content.  COLLABORATE 09 is next week, Sunday, May 3 through Thursday, May 7 in Orlando.  This year there will be over 1,000 technical sessions covering virtually every Oracle product. 

Integrigy's CTO, Stephen Kost, will be presenting three technical sessions:

Oracle Applications Users Group (OAUG)


Oracle Critical Patch Updates Unwrapped
Session #1936
Wednesday, May 6, 2009
9:45am - 10:45am

Independent Oracle Users Group (IOUG)


Oracle Critical Patch Updates: Insight and Understanding
Session #359
Wednesday, May 6, 2008
8:30am - 9:30am

Real World Database Auditing
Session #602
Tuesday, May 5, 2009
11:00 AM - 12:00 PM

See you in Orlando!
Categories:

April 17, 2009

Oracle Critical Patch Update - April 2009 - E-Business Suite Impact

Oracle released the eighteenth Critical Patch Update (CPU) on Tuesday, April 14, 2009 (CPU April 2009/CPUApr09). This quarter is the same as the previous sixteen with many patches and long hours in order to get all the security patches applied in a timely manner. Around 20 of the 43 vulnerabilities fixed impact the Oracle E-Business Suite.  Fortunately like the last few quarters, this quarter there are no new Oracle Application Server or Developer 6i patches required for the Oracle E-Business Suite 11i.

Again this quarter there are a number of database vulnerabilities that can be exploited by lowly privileged database accounts, including the APPLSYSPUB account.  Also, there are 2 denial of service vulnerabilities - one in the database listener and the other in the RAC Cluster Ready Services.

For the Application Server, no action is required for Oracle E-Business Suite 11i.  For R12, there is a serious vulnerability in OPMN which is installed and used and multiple issues in BI Publisher (formerly XML Publisher).

Oracle continues the push to keep all customers on recent versions by only certifying the CPU patches with 9.2.0.8, 10.1.0.5, 10.2.0.4, 11.1.0.6, and 11.1.07 for the database and ATG_PF.H RUP5 or RUP6 for the Oracle E-Business Suite 11i.

More information about the vulnerabilities and detailed recommendations on patching and testing is available at -

Oracle Oracle Critical Patch Update - April 2009 - E-Business Suite Impact