Today Oracle has released its quarterly patch update for October 2018. It fixes 301 vulnerabilities.
The main highlights are as follows:
ERPScan Research and Security Intelligence teams provide an analysis of the vulnerabilities closed by this Critical Patch Update.
Comparing with the previous CPU for July 2018 that jumped over a 330-issue mark and became the largest ever, this month’s patch update addresses 10% less vulnerabilities, see a bar chart below.
Oracle fixes 1119 security issues in total in 2018. It is worth mentioning that this number rests the same as it was in 2017. The graph below illustrates the trend and the increasing number of patches released by Oracle for each year from 2013 to 2018.
The patch updates touch a wide range of products. The affected product families are shown in a table and sorted in descending order of the closed issues.
| Product Family | Number of Patches |
|---|---|
| Fusion Middleware | 65 |
| MySQL | 38 |
| Retail Applications | 31 |
| PeopleSoft | 24 |
| Sun Systems Products Suite | 19 |
| E-Business Suite | 16 |
| Communications Applications | 14 |
| Virtualization | 14 |
| Java SE | 12 |
| Construction and Engineering Suite | 10 |
| Hospitality Applications | 9 |
| Hyperion | 9 |
| Database Server | 7 |
| JD Edwards Products | 6 |
| Supply Chain Products Suite | 6 |
| Insurance Applications | 5 |
| Enterprise Manager Products Suite | 4 |
| Food and Beverage Applications | 4 |
| Siebel CRM | 3 |
| Financial Services Applications | 2 |
| iLearning | 1 |
| Health Sciences Applications | 1 |
| Support Tools | 1 |
As seen from the table and illustrated in a pie chart, Fusion Middleware leads by the number of the closed issues.
The fact that Oracle has 430,000 applications customers from the wide range of industries in 175 countries makes it of the utmost importance to apply the released security patches.
This quarter’s CPU contains 162 patches for vulnerabilities affecting a scope of the most crucial business applications from Oracle, namely, PeopleSoft, E-Business Suite, Fusion Middleware, Retail, JD Edwards, Siebel CRM, Financial Services, Hospitality Applications, Supply Chain. It’s 54% of vulnerabilities found in Oracle products this quarter.
125 of these security vulnerabilities can be exploited remotely without entering credentials.
Oracle PeopleSoft is an application suite of business and industry solutions such as PeopleSoft Human Capital Management, Financial Management, Supplier Relationship Management, Enterprise Services Automation, and Supply Chain Management. As it manages a wide range of business processes and stores key data, a successful attack against PeopleSoft allows an attacker to steal or manipulate business information, depending on modules installed in an organization.
This quarter only, the vendor released 24 fixes (or 8% of the update) addressing this component, see a bar chart. 21 of them can be exploited over a network without requiring user credentials.
As seen from the graph, the number of vulnerabilities in PeopleSoft has fluctuated several times since October 2015 and raised from April to October 2018.
Oracle E-Business Suite (EBS) is the main business software developed by Oracle. As it manages a wide range of business processes and stores key data, a successful attack against Oracle EBS allows an attacker to steal and manipulate different business critical information, depending on modules installed in an organization.
This critical patch update contains 16 fixes for Oracle EBS, and 14 of the vulnerabilities may be remotely exploitable without authentication. The highest CVSS score is 8.2.
Oracle prepares Risk Matrices and associated documentation describing the conditions that are required to exploit a vulnerability, and the potential impact of a successful attack. The severity of the vulnerabilities is calculated via the Common Vulnerability Scoring System (CVSS ). This aims to help Oracle customers to fix the most critical issues first.
The most critical issues closed by the CPU are as follows:
It is highly recommended that organizations patch all those vulnerabilities to prevent business risks affecting their systems. Companies providing Oracle Security assessment and Oracle Penetration testing services should include these vulnerabilities in their checklists. The tests for the latest vulnerabilities in Oracle PeopleSoft are included in ERPScan Security Monitoring Suite for Oracle PeopleSoft.
The post Analyzing Oracle Security – Oracle Critical Patch Update for October 2018 appeared first on ERPScan.
*** This is a Security Bloggers Network syndicated blog from Blog – ERPScan authored by Research Team. Read the original post at: https://erpscan.com/press-center/blog/analyzing-oracle-security-oracle-critical-patch-update-for-october-2018/
Leading UK Credit Card Consumer Finance Company Uses Advanced Graph Analytics to Intercept Fraudulent Credit Card Applications, Boost Anti-Fraud Efforts…
Digital+ Partners Leads Continuation Funding Round in Growing Automated Threat Analysis & Detection Provider, Closing its Series B Round at…
For three years OpenWRT had a severe validation problem with its download package manager, until a fuzz tester found and…
It’s time to say a final “Goodbye” to Flash. (Or should that be “Good riddance”?) With earlier this week seeing…
1. Be a student of (information security, network security, cyber security). Always strive to know what the latest tactics, trends,…
This is the second in a series of blog posts that discuss how smart DNS resolvers can enhance ongoing network…