Oracle Security Blog RSS

  • Integrigy at COLLABORATE 09

    For those of you not familiar with COLLABORATE or have not previously attended, the Oracle Applications Users Group (OAUG), Independent Oracle Users Group (IOUG), and Quest have teamed together to host a user-driven event with exceptional content....
  • Oracle Critical Patch Update - April 2009 - E-Business Suite Impact

    Oracle released the eighteenth Critical Patch Update (CPU) on Tuesday, April 14, 2009 (CPU April 2009/CPUApr09). This quarter is the same as the previous sixteen with many patches and long hours in order to get all the security patches applied in a...
  • Oracle Critical Patch Update - January 2009 - E-Business Suite Impact

    Oracle released the seventeenth Critical Patch Update (CPU) on Tuesday, January 13, 2009 (CPU January 2009/CPUJan09). This quarter is the same as the previous sixteen with many patches and long hours in order to get all the security patches applied...
  • Oracle Critical Patch Update January 2009 Pre-Release Analysis

    Here is a brief analysis of the pre-release announcement for the upcoming January 2009 Oracle Critical Patch Update (CPU) - Overall, 41 security vulnerabilities are fixed in this CPU, which is an average number well within the range of previous...
  • Oracle Critical Patch Update April 2007 New Vulnerability Information

    New information has been released for an Oracle E-Business Suite 11i security vulnerability fixed as part of the April 2007 Critical Patch Update.  The vulnerability was discovered by Joxean Koret and the TippingPoint Zero Day Initiative...
  • Oracle E-Business Suite 12.0.6 - Security Enhancements

    The Oracle E-Business Suite R12 Release Update Pack (RUP6 or 12.0.6) was released on November 7, 2008.  This is the latest cumulative update patch for all product families including Applications Technology (ATG).  The patch is 2GB in size...
  • Urgent Oracle [BEA] WebLogic Security Patch (CVE-2008-3257)

    Oracle today released an urgent, out-of-cycle security patch for a critical flaw in the Apache Connector component (mod_weblogic) of the Oracle WebLogic Server (formerly BEA WebLogic Server).  The CVE ID is CVE-2008-3257.  The CVSS 2.0...
  • Oracle Security Advisories and CVE Identifiers

    In a major change to the Oracle security advisory process and Critical Patch Update documentation, CVE identifiers are now used in place of the Oracle proprietary numbering scheme (i.e., DB01, AS01, APP01, etc.).  Common Vulnerabilities and...
  • Oracle Critical Patch Update July 2008 Pre-Release Analysis

    Here is a brief analysis of the pre-release announcement for the upcoming July 2008 Oracle Critical Patch Update (CPU) - Overall, 45 security vulnerabilities are fixed in this CPU, which is an average number well within the range of previous...
  • OAUG eLearning: Oracle Critical Patch Update April 2008

    This quarters Oracle Critical Patch Update (CPU) was released on Tuesday, April 15th.   In order to provide a better understanding of the CPU, I will be presenting an Oracle Applications Users Group (OAUG) eLearning session on Thursday....
  • Oracle Critical Patch Update - April 2008 - E-Business Suite Impact

    Oracle released the fourteenth Critical Patch Update (CPU) last week.  This quarter is the same as the previous thirteen with many patches and long hours in order to get all the security patches applied in a timely manner.  Around 20 of...
  • Integrigy COLLABORATE 08 Presentations On-line

    The COLLABORATE 08 conference went very well this year with excellent attendance and, as usual, high quality and informative presentations.  The aspect I especially like about COLLABORATE as compared to other conferences is that it is user-...
  • Critical Patch Update April 2008 Pre-Release Analysis

    Here is a brief analysis of the pre-release announcement for the upcoming April 2008 Oracle Critical Patch Update (CPU) - Overall, 41 security vulnerabilities are fixed in this CPU, which is an average number well within the range of previous...
  • "Hundreds of Oracle Products"

    In the Oracle pre-release announcement for the April 2008 Critical Patch Update, one line in particular did catch my attention. I know Oracle has purchased many companies in the past few years.  So how many products does Oracle have?  Well...
  • COLLABORATE 08 Presentations

    For those of you not familiar with COLLABORATE or have not previously attended, the Oracle Applications Users Group (OAUG), Independent Oracle Users Group (IOUG), and Quest have teamed together to host a user-driven event with exceptional content....