Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Oracle to fix 73 security bugs next week

But Java SE and Java for Business are not set to be updated

Oracle plans to release a large number of security patches for its various software products next week, including six bug-fixes for its flagship database software.

All told, there will be 73 security vulnerabilities fixed across Oracle's various product lines. Oracle releases patches for all of its software - except the Java virtual machine -- quarterly, in a set of patches it calls the Critical Patch Update (CPU).

Next week's CPU is due on Tuesday. There are nine fixes set for Oracle Fusion middleware, 14 for the PeopleSoft Suite and eight for the JD Edwards Suite.

Two of the database flaws are considered critical, meaning they "may be exploited over a network without the need for a username and password," Oracle said in a statement posted to its website Thursday.

The updates are set to come one week after Microsoft issued one of the largest collections of security patches it has ever issued. They also come on the tail of Apple Mac OS X, Safari and iOS updates, released Thursday.

Oracle will patch many of its Sun products, including Solaris and some of the Java server software. However, the widely used Java SE and Java for Business client software are not scheduled to be updated in next week's release.

Oracle seems to be trying to put client-side Java on its quarterly Critical Patch Update schedule, but it's not quite there yet. While the company's Oct. 18 CPU will include the Java platform, the next scheduled Java fix is set for June 7. That's out of synch with the next CPU for the rest of Oracle's products, which is due July 19.

Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Apple, eSoft, etwork, FaceTime, IDG, JD Edwards, Microsoft, Oracle, PeopleSoft, S Central
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: oracle, patches, security, software
Latest Blog Posts
Whitepapers
  • Forrester Research | Your Enterprise Database Security Strategy 2010
    With increasingly sophisticated attacks and rising internal data theft, database security merits a stronger focus that goes beyond traditional authentication, authorization, and access control. Learn how to secure your database - Read this strategy guide.
    Learn more »
  • The State of Data Security
    Recognize how your data can become vulnerable, including the latest issues stemming from unprotected data on mobile devices and social media sites. Understand the compliance issues involved, and identify data protection strategies you can use to keep your company’s information both safe and compliant.
    Learn more »
  • Pathways Advanced ICT Leadership Development Program Brochure and Course Outline 2012
    Developed by the CIO executive Council in conjunction with Rob Livingstone Advisory, Pathways Advanced is a 12-month CIO delivered, small group, mentor based professional leadership development program. Pathways Advanced brings together best practice, thought leadership and business insights for today’s most promising ICT professionals
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments