Oracle critical security patch – April 2017
Oracle has released 300 security updates as part of the quarterly patch release cycle. The Oracle Critical Patch Update – April 2017 provides fixes for: Database Server, Oracle Secure Backup, Oracle Berkeley DB, Oracle API Gateway, Oracle Fusion Middleware Products, Enterprise Manager Base Platform,
Oracle has released 300 security updates as part of the quarterly patch release cycle. The Oracle Critical Patch Update – April 2017 provides fixes for: Database Server, Oracle Secure Backup, Oracle Berkeley DB, Oracle API Gateway, Oracle Fusion Middleware Products, Enterprise Manager Base Platform, Oracle E-Business Suite, Oracle Transportation Manager, PeopleSoft Applications, JD Edwards EnterpriseOne Tools, Siebel Applications, Oracle Commerce Guided Search / Oracle Commerce Experience Manager, Oracle Fusion Applications, Oracle Communications Applications, Oracle Financial Applications, Oracle Insurance Data Foundation, Oracle Healthcare Master Person Index, Oracle Hospitality OPERA 5 Property Services, Oracle Insurance Istream, Oracle Retail Applications, Oracle Utilities Applications, Oracle Primavera Products Suite, Oracle Java SE, Oracle and Sun Systems Products Suite, Oracle VM VirtualBox, Secure Global Desktop, Oracle MySQL Product Suite, Oracle Support Tools. These blogs talk about Oracle Critical Patch Update April 2017.
The CPUApr2017 Advisory addresses:
– Two (2) security vulnerabilities for the Oracle Database Server, Neither of these vulnerabilities may be remotely exploitable without authentication, i.e., none may be exploited over a network without requiring user credentials. These vulnerabilities requires a vulnerability management tool.
(CVE-2017-3486, CVE-2017-3567)
– One (1) security vulnerability for Oracle Secure Backup, this can be exploited remotely without authentication. Each of these vulnerabilities requires a patch management solution to mitigate them.
(CVE-2016-6290)
– Fourteen (14) security vulnerabilities for the Oracle Berkeley DB, None of these vulnerabilities may be remotely exploitable without authentication, i.e., none may be exploited over a network without requiring user credentials.
(CVE-2017-3604, CVE-2017-3605, CVE-2017-3606, CVE-2017-3607, CVE-2017-3608, CVE-2017-3609, CVE-2017-3610, CVE-2017-3611, CVE-2017-3612, CVE-2017-3613, CVE-2017-3614, CVE-2017-3615, CVE-2017-3616, CVE-2017-3617)
– Thirty one (31) security vulnerabilities for the Oracle Fusion Middleware, 20 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.
(CVE-2017-5638, CVE-2017-3553, CVE-2016-6303, CVE-2015-7501, CVE-2017-5638, CVE-2016-0714, CVE-2015-7501, CVE-2017-3230, CVE-2017-3540, CVE-2017-3542, CVE-2017-3543, CVE-2017-3625, CVE-2017-3545, CVE-2017-3541, CVE-2017-3601, CVE-2017-3602, CVE-2017-3554, CVE-2016-1181, CVE-2017-3596, CVE-2017-3499, CVE-2017-3506, CVE-2017-3507, CVE-2017-3531, CVE-2017-3593, CVE-2017-3595, CVE-2017-3591, CVE-2017-3594, CVE-2017-3597, CVE-2017-3626, CVE-2017-3598, CVE-2017-3603)
– One (1) security vulnerability for Oracle Hyperion, This can be exploited remotely without any authentication.
(CVE-2015-3237)
– Two (2) security vulnerabilities for Oracle Enterprise Manager Grid Control, These vulnerabilities may be remotely exploitable without authentication.
(CVE-2016-3092, CVE-2017-3518)
– Eleven (11) security vulnerabilities for Oracle E-Business Suite. Ten of these may be remotely exploitable without authentication.
(CVE-2017-3549, CVE-2017-3555, CVE-2017-3393, CVE-2017-3550, CVE-2017-3337, CVE-2017-3432, CVE-2017-3557, CVE-2017-3592, CVE-2017-3528, CVE-2017-3515,CVE-2017-3556)
– One (1) security vulnerability for Oracle Supply Chain Products Suite. This can not be exploited remotely without authentication.
(CVE-2017-3530)
– Sixteen (16) security vulnerabilities for the Oracle PeopleSoft Products. Eight of these may be remotely exploitable without authentication.
(CVE-2017-3519, CVE-2017-3547, CVE-2017-3577, CVE-2017-3570, CVE-2017-3520, CVE-2017-3548, CVE-2017-3546, CVE-2014-3596, CVE-2017- 3521, CVE-2017-3525, CVE-2017-3524, CVE-2017-3571, CVE-2017-3522, CVE-2017-3502, CVE-2017-3527, CVE-2017-3536)
– One (1) security vulnerability for Oracle JD Edwards Products.
(CVE-2017-3517)
– One (1) security vulnerability for Oracle Siebel CRM.
(CVE-2017-5638)
– Three (1) security vulnerabilities for Oracle Commerce.
(CVE-2017-3572, CVE-2016-6304, CVE-2016-2107)
– Eleven (11) security vulnerabilities for Oracle Communications Applications.
(CVE-2017-5638, CVE-2016-0729, CVE-2016-0635, CVE-2016-3092, CVE- 2013-5209, CVE-2016-6304, CVE-2012-0920, CVE-2017-3732, CVE-2013-2566, CVE-2017-3470, CVE-2015-0204)
– Forty seven (47) security vulnerabilities for Oracle Financial Services Applications.
– One (1) security vulnerability for Oracle Health Sciences Applications.
(CVE-2016-3092)
– Six (6) security vulnerabilities for the Oracle Hospitality Applications.
(CVE-2017-3574, CVE-2017-3568, CVE-2017-3573, CVE-2017-3569, CVE-2017-3552, CVE-2017-3560)
– One (1) security vulnerability for Oracle Insurance Applications.
(CVE-2015-7940)
– Thirty nine (39) security vulnerabilities for the Oracle Retail Applications.
– Seven (7) security vulnerabilities for the Oracle Utilities Applications.
(CVE-2016-5019, CVE-2014-0114, CVE-2016-3092, CVE-2016-3674, CVE-2016-3092, CVE-2017-3537, CVE-2012-5881)
– Seven (7) security vulnerabilities for the Oracle Primavera Products.
(CVE-2017-3503, CVE-2017-3508, CVE-2017-3500, CVE-2017-3583, CVE-2017-3579, CVE-2017-3501, CVE-2017-3732)
– Eight (8) security vulnerabilities for the Oracle Java SE.
(CVE-2017-3512, CVE-2017-3514, CVE-2017-3511, CVE-2017-3526, CVE-2017-3509, CVE-2017-3533, CVE-2017-3544, CVE-2017-3539)
– Twenty one (21) security vulnerabilities for the Oracle Sun Systems Products Suite. Eight of these may be remotely exploitable without authentication.
– Fifteen (15) security vulnerabilities for the Oracle Virtualization. Six of these vulnerabilities may be remotely exploitable without authentication.
– Forty (40) security vulnerabilities for Oracle MySQL. Eleven of these vulnerabilities may be remotely exploitable without authentication.
– Thirteen (13) security vulnerabilities for the Oracle Support Tools. Four of these may be remotely exploitable without authentication.
Detailed list of Affected Products and Components:
However, SecPod Saner detects these vulnerabilities and automatically fixes it by applying security updates. Furthermore, download Saner now and keep your systems updated and secure.
