Oracle Critical Patch Update for October 2016 Fixes 253 Vulnerabilities

  • 19 October 2016
  • 2 replies
  • 2 views

Userlevel 7
Badge +54
By Ionut Arghire on October 19, 2016
 
Oracle this week released its Critical Patch Update (CPU) for October 2016 to deliver a total of 253 new security fixes across multiple product families, nearly half of which can be exploited remotely without authentication.
 
Oracle products receiving the largest number of fixes this quarter include Oracle Communications Applications (36 patches), MySQL (31), Fusion Middleware (29), Financial Services Applications (24), and E-Business Suite (21). Oracle Database, Java SE, PeopleSoft, and Retail Applications received patches as well.
 
At 253 fixes, the October 2016 CPU is the second largest for the year, after the July CPU set a record at 276 patches. This month, Oracle resolved numerous Critical flaws in its products (over a dozen of the vulnerabilities had a CVSS base score above 9), including one vulnerability in the HTTP service of the Oracle E-Business Suite.
 
Full Article

2 replies

Userlevel 7
Badge +56
It's now out to install and make sure if you have a 64bit OS to download and install both the 32bit and 64bit versions and be on the lookout for any unwanted add-ons if offered. PUA's: https://community.webroot.com/t5/Techie-KB/How-to-Remove-Potentially-Unwanted-Applications/ta-p/40744
 
Here to download: http://www.oracle.com/technetwork/java/javase/downloads/jre8-downloads-2133155.html
 
Daniel
Userlevel 7
Thanks to you, both, Jasper & Daniel...for the heads up.
 
I had managed to some how miss this important update...but all sorted now.
 
And I noted that whilst the installer tried to intriduce Yahoo as the default homepage...:D...the detection & uninstall of out of date Java versions was offered...which I thought was a nice touch. :D
 
Regards, Baldrick
 
 

Reply