iTnews Asia
  • Home
  • News
  • Security

Oracle issues mammoth patch collection

Oracle issues mammoth patch collection

Mostly fixing third-party utilities.

By Richard Chirgwin on Oct 19, 2023 12:21PM

Oracle’s quarterly patch release fixes an eye-watering 387 security vulnerabilities, but only 14 of them are rated critical (with a CVSS score greater than 9).

A critical Apache Commons ByteCode engineering library (BCEL) bug affects the company’s Communications Applications.

CVE-2023-34462 is an API bug that gives an attacker control over the bytecode produced by the library, and was first disclosed in July 2022.

The bug also affects PeopleSoft, Communications, Insurance Applications, Retail Applications, Utilities Applications, and Fusion Middleware.

Oracle Communications inherits a critical bug in OpenSSH, CVE-2023-38408, patched by the project in in September 2023; another in PHP patched in August, CVE-2023-3824; and CVE-2022-36944, a deserialisation bug in Scala.

Oracle Financial Services Applications gets fixes for three critical bugs: CVE-2023-22946 in Apache Spark (also fixed in Oracle Analytics), CVE-2022-1471 in SnakeYaml (also fixed in Retail Applications, Financial Services, and Banking), and CVE-2023-20873 in Spring Boot.

Among its eight fixes, the company’s Fusion middleware has three critical bugs in its core component: CVE-2023-22069, CVE-2023-22072, and CVE-2023-22089, all described as “easily exploited” vulnerabilities allowing an attacker to compromise the WebLogic server.

Oracle Analytics inherits two further bugs from the Apache project: CVE-2022-26612 in the Hadoop unTar function; and CVE-2022-33980 in the Apache Commons configuration utility.

Hyperion inherits yet another Apache bug: CVE-2023-25690, a web request smuggling vulnerability in the project’s HTTP server.

Finally, a Spring security bug, CVE-2023-34034, shows up in MySQL and Communications.

Oracle's critical patch update is here.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
apache openssh oracle security spring

Related Articles

  • Ransomware gang Qilin claims attack on Japan’s Asahi breweries
  • IMDA and Enterprise Singapore launch SME-focused cybersecurity initiative
  • Cyberthreats are now targeting critical infrastructure on a larger scale
  • Gemini vulnerabilities threaten potential exposure of user data
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

IMDA and Enterprise Singapore launch SME-focused cybersecurity initiative

IMDA and Enterprise Singapore launch SME-focused cybersecurity initiative

Cyberthreats are now targeting critical infrastructure on a larger scale

Cyberthreats are now targeting critical infrastructure on a larger scale

Ransomware gang Qilin claims attack on Japan’s Asahi breweries

Ransomware gang Qilin claims attack on Japan’s Asahi breweries

Gemini vulnerabilities threaten potential exposure of user data

Gemini vulnerabilities threaten potential exposure of user data

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.