Skip to main content

Oracle Products Multiple vulnerabilities

Last Update Date: 16 Oct 2014 14:37 Release Date: 16 Oct 2014 3466 Views

RISK: High Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities have been identified in various Oracle products and components, which could be exploited by attackers to denial of service, escalation of privilege, sensitive information disclosure and data tampering.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • Oracle Database 11g Release 1, version 11.1.0.7
  • Oracle Database 11g Release 2, versions 11.2.0.3, 11.2.0.4
  • Oracle Database 12c Release 1, versions 12.1.0.1, 12.1.0.2
  • Oracle Application Express, versions prior to 4.2.6
  • Oracle Fusion Middleware 11g Release 1, versions 11.1.1.5, 11.1.1.7
  • Oracle Fusion Middleware 11g Release 2, versions 11.1.2.1, 11.1.2.2, 11.1.2.4
  • Oracle Fusion Middleware 12c, versions 12.1.1.0, 12.1.2.0, 12.1.3.0
  • Oracle Fusion Applications, versions 11.1.2 through 11.1.8
  • Oracle Access Manager, versions 11.1.1.5, 11.1.1.7, 11.1.2.1, 11.1.2.2
  • Oracle Adaptive Access Manager, versions 11.1.1.5, 11.1.1.7, 11.1.2.1, 11.1.2.2
  • Oracle Endeca Information Discovery Studio versions 2.2.2, 2.3, 2.4, 3.0, 3.1
  • Oracle Enterprise Data Quality versions 8.1.2, 9.0.11
  • Oracle Identity Manager, versions 11.1.1.5, 11.1.1.7, 11.1.2.1, 11.1.2.2
  • Oracle JDeveloper, versions 10.1.3.5, 11.1.1.7, 11.1.2.4, 12.1.2.0, 12.1.3.0
  • Oracle OpenSSO version 3.0-04
  • Oracle WebLogic Server, versions 10.0.2, 10.3.6, 12.1.1, 12.1.2, 12.1.3
  • Application Performance Management, versions prior to 12.1.0.6.2
  • Enterprise Manager for Oracle Database Releases 10g, 11g, 12c
  • Oracle E-Business Suite Release 11i version 11.5.10.2
  • Oracle E-Business Suite Release 12 versions 12.0.4, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, 12.2.4
  • Oracle Agile PLM, versions 9.3.1.2, 9.3.3
  • Oracle Transportation Management, versions 6.1, 6.2, 6.3.0 through 6.3.5
  • Oracle PeopleSoft Enterprise HRMS, version 9.2
  • Oracle PeopleSoft Enterprise PeopleTools, versions 8.52, 8.53, 8.54
  • Oracle JD Edwards EnterpriseOne Tools, version 8.98
  • Oracle Communications MetaSolv Solution, versions MetaSolv Solution: 6.2.1.0.0, LSR: 9.4.0, 10.1.0, ASR: 49.0.0
  • Oracle Communications Session Border Controller, version SCX640m5
  • Oracle Retail Allocation, versions 10.0, 11.0, 12.0, 13.0, 13.1, 13.2
  • Oracle Retail Clearance Optimization Engine, versions 13.3, 13.4, 14.0
  • Oracle Retail Invoice Matching, versions 11.0, 12.0, 12.0 IN, 12.1, 13.0, 13.1, 13.2, 14.0
  • Oracle Retail Markdown Optimization, versions 12.0, 13.0, 13.1, 13.2, 13.4
  • Oracle Health Sciences Empirica Inspections, versions 1.0.1.0 and prior
  • Oracle Health Sciences Empirica Signal, versions 7.3.3.3 and prior
  • Oracle Health Sciences Empirica Study, versions 3.1.2.0 and prior
  • Oracle Primavera Contract Management, versions 13.1, 14.0
  • Oracle Primavera P6 Enterprise Project Portfolio Management, versions 7.0, 8.1, 8.2, 8.3
  • Oracle JavaFX, version 2.2.65
  • Oracle Java SE, versions 5.0u71, 6u81, 7u67, 8u20
  • Oracle Java SE Embedded, version 7u60
  • Oracle JRockit, versions R27.8.3, R28.3.3
  • Oracle Fujitsu server, versions M10-1, M10-4, M10-4S
  • Oracle Solaris, versions 10, 11
  • Oracle Secure Global Desktop, versions 4.63, 4.71, 5.0, 5.1
  • Oracle VM VirtualBox, versions prior to 4.1.34, 4.2.26, 4.3.14
  • Oracle MySQL Server, versions 5.5.39 and earlier, 5.6.20 and earlier

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Apply Oracle Critical Patch Update - October 2014

Vulnerability Identifier


Source


Related Link