Personal tools
You are here: Home Oracle Security Blog Archive 2010

Entries For: 2010

December 06, 2010

Webinar: Internal Auditor Primer - Oracle E-Business Suite Security Risks

Internal Auditor Primer: Oracle E-Business Suite Security Risks
Thursday, December 9, 2010 1:00 PM - 2:00 PM EST

Internal Auditors are trained to understand the financial aspects and the end user functionally of an ERP solution. However, most Internal Auditors have not been trained in the security features of an ERP system. This one hour auditing primer webinar will highlight the basic security that should be found within all implemented Oracle E-Business Suite (OEBS) systems.

Topics include:
  • Compliance issues regarding PCI, HIPAA, SOX
  • Protection of Sensitive Data within the OEBS
  • Best Practices of securing the OEBS
  • Concern and risk with user privileges, excessive access, insecure access
  • Secure external access to Oracle EBS (iStore, iSupplier, iRecruitment, iSupport, etc.

Click here to register for this webinar.

November 16, 2010

Upcoming Webinar: IT Security Briefing: Security Risks in the Oracle Database

IT Security Briefing: Security Risks in the Oracle Database
Thursday, November 18, 2:00pm - 3:00pm EST

Most IT Security personnel are familiar with the security requirements of networks and operating systems.  But many in IT Security are not aware of the security risks inherent in their company’s Oracle production databases.  Issues concerning the protection of sensitive data, restricting excessive user access privileges, and implementing database activity monitoring are not given serious consideration.  This one hour educational session will highlight the security risks and safeguards that should be found in every production database.

Topics include:

  • Database inspection for regulatory compliance.
  • Protection of sensitive data (credit card data, social security numbers, payroll data, etc)
  • Database appraisal for excessive user privileges, unwarranted access, and access to insecure areas
  • Validating internal database security standards – written and implemented.
  • Confirming on-going database activity monitoring is implemented to ensure business requirements are satisfied, all attack vectors are covered, and alerting/reporting is active.

Click here to register for this IT Security Briefing on Oracle Database security.
Categories:

October 27, 2010

Upcoming Webinar: Oracle Critical Patch Update October 2010 - Oracle Database Impact

Oracle October 2010 CPU - Oracle Database Impact
Thursday, October 28, 2:00pm - 3:00pm EDT

Every quarter, Oracle releases a Critical Patch Update (CPU) that fixes a number of security vulnerabilities in the Oracle Database. This quarterly educational session will focus on the October 2010 CPU and the impact on the Oracle Database. The topics will include:
  • A review of the security vulnerabilities fixed in this CPU,
  • An analysis of the required CPU patches,
  • A discussion of patching including CPUs vs. PSUs.

Example vulnerabilities will be demonstrated in order to show how easy it is exploit many of the fixed security bugs.

Click here to register for the Oracle Database webinar.

October 20, 2010

Upcoming Webinars: Oracle Critical Patch Update October 2010

Integrigy's CTO, Stephen Kost, will be presenting a series of webinars on Oracle's Critical Patch Update for October 2010.

Oracle October 2010 CPU - Oracle E-business Suite Impact
Thursday, October 21, 2:00pm - 3:00pm EDT

This quarterly eLearning session will focus on the October 2010 CPU and the impact on E-Business Suite environments.

Topics will include;
  • a review of the security vulnerabilities fixed in the CPU,
  • an analysis of the required CPU patches,
  • a discussion of a high-level patch strategy.

Example vulnerabilities will be demonstrated in order to show how easy it is exploit many of the fixed security bugs.

Click here to register for the Oracle E-Business Suite webinar.


Oracle October 2010 CPU - Oracle Database Impact

Thursday, October 28, 2:00pm - 3:00pm EDT

Every quarter, Oracle releases a Critical Patch Update (CPU) that fixes a number of security vulnerabilities in the Oracle Database. This quarterly eLearning session will focus on the October 2010 CPU and the impact on the Oracle Database. The topics will include:
  • A review of the security vulnerabilities fixed in this CPU,
  • An analysis of the required CPU patches,
  • A discussion of patching including CPUs vs. PSUs.

Example vulnerabilities will be demonstrated in order to show how easy it is exploit many of the fixed security bugs.

Click here to register for the Oracle Database webinar.

October 14, 2010

Is the Oracle Critical Patch Update for October 2010 Massive?

The news reports describing the October 2010 Oracle Critical Patch Update (CPU) are using terms like "giant", "massive", and practically every other known synonym for a really big security patch release.  These news reports must be resonating with CIOs and CSOs as Integrigy has received a number of client calls and a huge response to our upcoming webinars detailing this CPU.

As always a little perspective and analysis is required to quantify what is actually in the CPU and the risk to an organization.  First, lets look at the 85 vulnerabilities patched in the CPU to see how this CPU compares with previous CPUs -

  • 75% (63 of 85) of the bugs fixed in this CPU are in products Oracle has acquired since the release of the first CPU in January 2005.
  • 40% (36 of 85) of the bugs fixed in this CPU are in products Oracle has owned for less than a year (Sun).
  • Only 7 database vulnerabilities are fixed this quarter where the historical average is 16.5 database bugs per quarter.
  • Only 6 E-Business Suite vulnerabilities are fixed this quarter where the historical average is 9 bugs per quarter.

A more detailed look at the security bug count and maximum CVSS score by quarter shows this CPU for the Oracle Database and Oracle E-Business Suite is average or slightly below for both bug count and maximum CVSS score.  Integrigy's preliminary analysis of this CPU shows 4 of the 7 database vulnerabilities can be exploited with no database credentials or just CREATE SESSION system privilege, which is consistent with previous CPUs - the other 3 vulnerabilities actually require advanced or infrequently granted privileges or roles like EXECUTE_CATALOG_ROLE.

Clearly for the Oracle Database and Oracle E-Business Suite, this CPU is no different than the previous twenty-three CPUs and should be handled with the same processes and prioritization as previous CPUs.

Upcoming Integrigy Oracle Critical Patch Update Webinars

Oracle October 2010 CPU E-Business Suite Impact Webinar
Thursday, October 21, 2-3pm EDT

Oracle October 2010 CPU Oracle Database Impact Webinar
Thursday, October 28, 2-3pm EDT

October 10, 2010

Oracle Critical Patch Update October 2010 Pre-Release Analysis

Here is a brief analysis of the pre-release announcement for the upcoming October 2010 Oracle Critical Patch Update (CPU) -
  • Overall, 50 Oracle security vulnerabilities are fixed in this CPU, which is a average number and well within the range of previous CPUs (Jul-10=38, Apr-10=31, Jan-10=24, Oct-09=38, Jul-09=30, Apr-09=43, Jan-09=41, Oct-08=36, Jul-08=45, Apr-08=41, Jan-08=26, Oct-07=51, Jul-07=45, Apr-07=36, Jan-07=51, Oct-06=101, Jul-06=62, Apr-06=34, Jan-06=80).  These numbers have been normalized for Oracle products and excludes any Sun products.
  • The Oracle product and vulnerability mix appears to be similar to previous CPUs.  All CPU supported Oracle Database and Oracle E-Business Suite versions are included.  The list of supported versions is getting very short and should be carefully reviewed to determine if version upgrades are required prior to applying the CPU security patches -
        • Database = 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 for major platforms
        • Application Server = 10.1.2.3.0, 10.1.3.5.0, 11.1.1.1.0, 11.1.1.2.0
        • E-Business Suite = 11.5.10.x, 12.0.x, and 12.1.x
  • This is the first CPU to exclude 9.2.0.8 as extended support ended July 2010.  The only other major change is the inclusion of Oracle Application Server/Fusion Middleware versions 10.1.3.5.0 and 11.1.1.x.
  • The highlight of this CPU is 6 of 8 Oracle Application Server/Fusion Middleware security vulnerabilities are remotely exploitable without authentication.  The vulnerabilities are in BI Publisher, BPEL Console, Cabo/UIX, Forms, OID, and Perl components.
  • Integrigy will be presenting more information on this CPU in the following webinars: (1) Oracle October 2010 CPU E-Business Suite Impact Webinar Thursday, October 21, 2pm ET and (2) Oracle October 2010 CPU Oracle Database Impact Webinar Thursday, October 28, 2pm ET.

Oracle Database
  • There are 7 database vulnerabilities and one is remotely exploitable without authentication.
  • Since at least one database vulnerability has a CVSS 2.0 metric of 7.5 (practical maximum for a database vulnerability), this is a fairly important CPU.  Most likely, any database account, even a lowly privileged account, will be able to gain full-control of the database by exploiting the vulnerability.
Oracle Application Server
  • There are 8 new Oracle Application Server vulnerabilities, 6 of which are remotely exploitable without authentication.  All the vulnerabilities appear to be in components not normally exposed externally.

Oracle E-Business Suite 11i and R12
  • There are 6 new Oracle E-Business Suite 11i and R12 vulnerabilities, 5 of which are remotely exploitable without authentication.
  • The vulnerabilities are in the Oracle Applications Manager, Oracle Applications Technology Stack, Oracle E-Business Intelligence, Oracle iRecruitment, and Oracle Territory Management.  Of most interest will be the vulnerabilities in iRecruitment and these might exploitable in externally accessible web pages.  Customers running iRecruitment should prepare to apply the patches immediately.

Planning Impact
  • We anticipate the criticality of this quarter's CPU will be in-line with previous CPUs.  The only exception may be if the remotely exploitable Oracle Database vulnerabilities are more significant than previous vulnerabilities in the networking components.
  • As with all previous CPUs, this quarter's security patches should be deemed critical and you should adhere to the established procedures and timing used for previous CPUs.
  • Oracle E-Business Suite customers with externally facing implementations should carefully review the remotely exploitable vulnerabilities in iRecruitment to determine if these pages are blocked by the URL firewall.  If any of the vulnerable web pages are externally accessible, customers should look to immediately patch these environments.

Oracle Application Server Fastcgi Echo Vulnerability Reports

A potential and unconfirmed cross-site scripting (XSS) vulnerability in the Oracle Application Server has been reported on the Full Disclosure mailing list.  The vulnerability is in the FastCGI module delivered with the Apache httpd server that is incorporated into the Oracle Application Server.  Integrigy has not confirmed the vulnerability as the author has not released details but the author claims this XSS vulnerability is different than those previously fixed in the fcgi-bin echo programs.

Regardless if a vulnerability does or does not exist, the FastCGI echo programs (echo and echo2) should be always removed or disabled in all Oracle Application Servers implementations as they can provide information at an attacker.  To verify if the echo program is installed try http://<host>:<port>/fcgi-bin/echo.

In Oracle's Best Practices for Securing the Oracle E-Business Suite (Metalink Notes 189367.1 page 17 and 403537.1 page 16), there is a recommendation to either remove the reference to fcgi-bin or disable fastcgi.  With AutoConfig, the following lines can be inserted into the custom_apache.conf file.

<Location "^/fcgi-bin/echo.*$">
Order deny,allow
Deny from all
</Location>


Oracle E-Business Suite 11i (11.5.10)
For 11.5.10.x with a recent version of the AutoConfig templates installed (TXK AutoConfig Templates Rollup Patch I or greater), there is no issue as there is a typo in the AutoConfig templates in which the fcgi-bin directory is set to $IAS_TOP/Apache/fcgi-bin rather than $IAS_TOP/Apache/Apache/fcgi-bin.

Oracle E-Business Suite R12 (12.0)
The echo program in 12.0.x is enabled with no restrictions, although in the environments we test echo and echo2 always returned server errors when executing.  We recommend all 12.0 implementations add the above restriction to echo and echo in the custom.conf file.

Oracle E-Business Suite R12 (12.1)
The AutoConfig templates for 12.1 (apps.conf) do include a specific restriction on access to fcgi-bin/echo and fcgi-bin/echo2 in the apps.conf file and the FastCGI module is not loaded (httpd.conf).

September 14, 2010

Oracle CPU Dates Shifted by a Week in 2011

Oracle has announced a slight change to the release schedule for Critical Patch Update (CPU) releases starting in 2011.  Rather than release on the Tuesday closest to the 15th of the month, now it will be the Tuesday closest to the 17th.  The intention of this shift is to provide more of a buffer for the January release to accommodate year-end close and vacations around the Christmas and New Years holidays.  Therefore, some of the CPU release dates have shifted by a week.

We anticipate no customer impact from this change.  Except for holidays and conferences, the timing of the CPU releases seldom impact organizations or implementations.  For 2011, the April 2011 CPU release on April 19th will be the week after the COLLABORATE 2011 conference (April 10-14) and the October 2011 CPU release will several weeks before Oracle OpenWorld (October 2-6).

For planning purposes, the upcoming CPU releases do come close to a number of holidays as follows -

October 2010 - Tuesday October 12
Monday October 11 - Columbus Day (US)
Monday October 11 - Thanksgiving Day (Canada)

January 2011 - Tuesday January 18
Monday January 17 - Martin Luther King Day (US)

April 2010 - Tuesday April 19
Friday April 22 - Good Friday (US/Canada/UK/Australia)
Sunday April 24 - Easter (US/Canada/UK/Australia)

September 13, 2010

Webinar: Oracle E-Business Suite Security Risks Primer for Internal Auditors

Oracle E-Business Suite Security Risks Primer for Internal Auditors
Tuesday, September 14, 2010 1:00 PM - 2:00 PM EDT

Internal Auditors are trained to understand the financial aspects and the end user functionally of an ERP solution. However, most Internal Auditors have not been trained in the security features of an ERP system. This one hour auditing primer webinar will highlight the basic security that should be found within all implemented Oracle E-Business Suite (OEBS) systems.

Topics include;
• Compliance issues regarding PCI, HIPAA, SOX
• Protection of Sensitive Data within the OEBS
• Best Practices of securing the OEBS
• Concern and risk with user privileges, excessive access, insecure access
• Secure external access to Oracle EBS (iStore, iSupplier, iRecruitment, iSupport, etc.

Click here to register for this webinar.

July 28, 2010

Upcoming Webinar: Oracle Critical Patch Update July 2010 Database Impact

Oracle July 2010 CPU - Oracle Database Impact
Thursday, July 29, 2:00pm - 3:00pm EDT

Every quarter, Oracle releases a Critical Patch Update (CPU) that fixes a number of security vulnerabilities in the Oracle Database. This quarterly eLearning session will focus on the July 2010 CPU and the impact on the Oracle Database. The topics will include:
  • A review of the security vulnerabilities fixed in this CPU,
  • An analysis of the required CPU patches,
  • A discussion of patching including CPUs vs. PSUs.

Example vulnerabilities will be demonstrated in order to show how easy it is exploit many of the fixed security bugs.

Click here to register for this webinar.

July 11, 2010

Oracle Critical Patch Update July 2010 Pre-Release Analysis

Here is a brief analysis of the pre-release announcement for the upcoming July 2010 Oracle Critical Patch Update (CPU) -
  • Overall, 38 Oracle security vulnerabilities are fixed in this CPU, which is a below average number but well within the range of previous CPUs (Apr-10=31, Jan-10=24, Oct-09=38, Jul-09=30, Apr-09=43, Jan-09=41, Oct-08=36, Jul-08=45, Apr-08=41, Jan-08=26, Oct-07=51, Jul-07=45, Apr-07=36, Jan-07=51, Oct-06=101, Jul-06=62, Apr-06=34, Jan-06=80).  These numbers have been normalized for Oracle products and excludes any Sun products.
  • The Oracle product and vulnerability mix appears to be similar to previous CPUs.  All CPU supported Oracle Database and Oracle E-Business Suite versions are included.  The list of supported versions is getting very short and should be carefully reviewed to determine if version upgrades are required prior to applying the CPU security patches -
        • Database = 9.2.0.8, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 for major platforms
        • Application Server = 10.1.2.3.0
        • E-Business Suite = 11.5.10.x, 12.0.x, and 12.1.x
  • The highlight of this CPU is 4 of 6 Oracle Database security vulnerabilities are remotely exploitable without authentication.  It is rare to have a single remotely exploitable without authentication vulnerability in the database.  Most likely these 4 vulnerabilities are in the Listener, Net Foundation Layer, Network Layer, and/or APEX Application Builder.  If the remotely exploitable vulnerabilities are in the Listener component, then this could only be a denial of service vulnerabilities.
  • There are no major version support changes in for this CPU.
  • Integrigy will be presenting more information on this CPU in the following webinars: (1) Oracle July 2010 CPU E-Business Suite Impact Webinar Thursday, July 22, 2pm ET and (2) Oracle July 2010 CPU Oracle Database Impact Webinar Thursday, July 29, 2pm ET.

Oracle Database
  • There are 6 database vulnerabilities and four are remotely exploitable without authentication.
  • Since at least one database vulnerability has a CVSS 2.0 metric of 7.8 (practical maximum for a database vulnerability), this is a fairly important CPU.  Most likely, any database account, even a lowly privileged account, will be able to gain full-control of the database by exploiting the vulnerability.
Oracle Application Server
  • There are seven new Oracle Application Server vulnerabilities, five of which are remotely exploitable without authentication.  For Oracle Application Server implementations, there is only one vulnerability in the Application Server Control.  Usually, vulnerabilities in the control utilities are only locally exploitable and require a local operating system account to exploit.

Oracle E-Business Suite 11i and R12
  • There are 7 new Oracle E-Business Suite 11i and R12 vulnerabilities, five of which are remotely exploitable without authentication.
  • The vulnerabilities are in the Oracle Advanced Product Catalog, Oracle Applications Framework (OAF), Oracle Applications Manager, and Oracle Knowledge Management.  Of most interest will be the vulnerabilities in the Oracle Applications Framework (OAF) and these might exploitable in externally accessible web pages.

Planning Impact
  • We anticipate the criticality of this quarter's CPU will be in-line with previous CPUs.  The only exception may be if the remotely exploitable Oracle Database vulnerabilities are more significant than previous vulnerabilities in the networking components.
  • As with all previous CPUs, this quarter's security patches should be deemed critical and you should adhere to the established procedures and timing used for previous CPUs.
  • Oracle E-Business Suite customers with externally facing implementations should carefully review the remotely exploitable vulnerabilities in the Oracle Applications Framework to determine if these pages are blocked by the URL firewall.  If any of the vulnerable web pages are externally accessible, customers should look to immediately patch these environments.

July 09, 2010

Upcoming Webinars: Oracle Critical Patch Update July 2010

Integrigy's CTO, Stephen Kost, will be presenting a series of webinars on Oracle's Critical Patch Update for July 2010.

Oracle July 2010 CPU - Oracle E-business Suite Impact
Thursday, July 22, 2:00pm - 3:00pm EDT

This quarterly eLearning session will focus on the July 2010 CPU and the impact on E-Business Suite environments.

Topics will include;
  • a review of the security vulnerabilities fixed in the CPU,
  • an analysis of the required CPU patches,
  • a discussion of a high-level patch strategy.

Example vulnerabilities will be demonstrated in order to show how easy it is exploit many of the fixed security bugs.

Click here to register for the Oracle E-Business Suite webinar.


Oracle July 2010 CPU - Oracle Database Impact

Thursday, July 29, 2:00pm - 3:00pm EDT

Every quarter, Oracle releases a Critical Patch Update (CPU) that fixes a number of security vulnerabilities in the Oracle Database. This quarterly eLearning session will focus on the July 2010 CPU and the impact on the Oracle Database. The topics will include:
  • A review of the security vulnerabilities fixed in this CPU,
  • An analysis of the required CPU patches,
  • A discussion of patching including CPUs vs. PSUs.

Example vulnerabilities will be demonstrated in order to show how easy it is exploit many of the fixed security bugs.

Click here to register for the Oracle Database webinar.

May 25, 2010

Upcoming IOUG Webinar - A Journey Through Enterprise Database Security for DBAs

Integrigy's CTO, Stephen Kost, will be presenting an Independent Oracle User's Group (IOUG) educational webinar as part of IOUG's Database Security Technical Education Series.

A Journey Through Enterprise Database Security for DBAs
Stephen Kost, Integrigy
Wednesday, May 26, 1:00pm - 2:00pm CT

This presentation is intended for Database Administrators. It will detail the enterprise database security requirements, regulatory requirements and monitoring of databases.

Click here to register for the webinar.

The webinar is free for IOUG Full Members and $49 for Associate Members and Non-members.
Categories:

April 15, 2010

Integrigy Oracle CPU Virtual Session Live from COLLABORATE 10

For those of you unable to attend the OAUG/IOUG COLLABORATE 10 User Conference in Las Vegas next week, the conference is offering a virtual experience of the conference.  There will be 41 sessions available via webinar live from Las Vegas.  Integrigy is pleased to announce that the following session is included in the roster of Plug-in to Vegas virtual sessions -

Oracle Critical Patch Updates Unwrapped
Session #330
Tuesday, April 20, 2010
2:00pm - 3:00pm

March 30, 2010

Integrigy at COLLABORATE 10

For those of you not familiar with COLLABORATE or have not previously attended, the Oracle Applications Users Group (OAUG), Independent Oracle Users Group (IOUG), and Quest have teamed together to host a user-driven event with exceptional content.  COLLABORATE 10 is Sunday, April 18, 2010 through Thursday, April 22, 2010 in Las Vegas.  This year there will be over 1,000 technical sessions covering virtually every Oracle product. 

If you are attending and would like to chat about the latest developments in Oracle security or discuss specific security challenges you might be facing, drop me a note and we can arrange to meet.

Integrigy's CTO, Stephen Kost, will be presenting three technical sessions on securing Oracle products and participating on two panels.

Oracle Applications Users Group (OAUG)


Leveraging Oracle Database Security Technologies with Oracle E-Business Suite
Session #4556
Monday, April 19, 2010
10:45am - 11:45am

Panel: Governance, Risk & Compliance SIG Meeting
Session #4699
Tuesday, April 20, 2010
8:00am - 9:00am

Panel: Securing the E-Business Suite - Expert And Best Practices Panel
Session #3676
Wednesday, April 21, 2010
9:15am - 10:15am

Independent Oracle Users Group (IOUG)


Oracle Critical Patch Updates Unwrapped
Session #330
Tuesday, April 20, 2010
2:00pm - 3:00pm

Is Your Auditing Failing You?
Session #600
Thursday, April 22, 2010
11:00am - 12:00pm
(Note: the time for this presentation has changed)

See you in Las Vegas!
Categories:

January 08, 2010

Oracle Critical Patch Update January 2010 Pre-Release Analysis

Here is a brief analysis of the pre-release announcement for the upcoming January 2010 Oracle Critical Patch Update (CPU) -
  • Overall, 24 security vulnerabilities are fixed in this CPU, which is a below average number but well within the range of previous CPUs (Oct-09=38, Jul-09=30, Apr-09=43, Jan-09=41, Oct-08=36, Jul-08=45, Apr-08=41, Jan-08=26, Oct-07=51, Jul-07=45, Apr-07=36, Jan-07=51, Oct-06=101, Jul-06=62, Apr-06=34, Jan-06=80).
  • The product and vulnerability mix appears to be similar to previous CPUs.  All CPU supported Oracle Database, Oracle Application Server, and Oracle E-Business Suite versions are included.  The list of supported versions is getting very short and should be carefully reviewed to determine if version upgrades are required prior to applying the CPU security patches -
        • Database = 9.2.0.8, 10.1.0.5, 10.2.0.3, 10.2.0.4, and 11.1.0.7 for major platforms
        • Application Server = 9.0.4.3, 10.1.2, and 10.1.3
        • E-Business Suite = 11.5.10.x, 12.0.x, and 12.1.x
  • The highlight of this CPU are 2 remotely exploitable without authentication vulnerabilities in the Oracle Database.  It is rare to have a single remotely exploitable without authentication vulnerability in the database.  Most likely these 2 vulnerabilities are in the Listener, APEX Application Builder, and/or Secure Backup.  If the remotely exploitable vulnerabilities are in the Listener component, then this could be a significant and high priority CPU.
  • There are no major version support changes in for this CPU.

Oracle Database
  • There are 10 database vulnerabilities and two are remotely exploitable without authentication.
  • Since at least one database vulnerability has a CVSS 2.0 metric of 10.0, this is a strong indication there a buffer overflow in the Listener component that is remotely exploitable without authentication.  Most likely, the CVSS metric for Windows will be 10.0 and will be 7.5 for Unix/Linux (even though you will be able to fully compromise the database).
Oracle Application Server
  • There are three new Oracle Application Server vulnerabilities, all of which are remotely exploitable without authentication.  The affected components are Access Manager Identify Server and Oracle Containers for J2EE.  With maximum CVSS 2.0 metric of 5.0, these could be cross-site scripting (XSS) vulnerabilities based on the scores and components.

Oracle E-Business Suite 11i and R12
  • There are 3 new Oracle E-Business Suite 11i and R12 vulnerabilities, all of which are remotely exploitable without authentication.
  • The vulnerabilities are in the CRM Technical Foundation (mobile), AOL, and HRMS.  Of most interest will be if the AOL vulnerability is in an externally accessible web page.

Planning Impact
  • The criticality of this quarter's CPU is in-line with previous CPUs. 
  • As with all previous CPUs, this quarter's security patches should be deemed critical and you should adhere to the established procedures and timing used for previous CPUs.