October 2012 Critical Patch Update Advisory from Oracle
Any and most software today is vulnerable to security concerns. Oracle, after being a victim to a successful threat to its security has introduced Critical Patch Update or CPUs, patches that help fix multiple security vulnerabilities that are often found in various customers' systems. It is important that customers using Oracle solutions apply these patches as soon as they are made available. It is important to understand that these patches are cumulative in nature, where the current patch is updated with all the previous patches but it is often seen that the company only has to implement the changes in the current patch rather than go on implementing everything. Read on to find out more about how these patches are useful and what software or solution they help best.
- Common products and solutions affected by vulnerabilities: this particular critical patch update deals with the vulnerabilities that are usually found in products like Oracle Database, Oracle Fusion Middleware, Oracle forms and reports, Oracle Identity Management, Oracle JRockit Versions, Oracle MYSQL Server and many others
-
Patch Availability: As mentioned earlier, this patch update includes patches for all solutions or software, including Oracle database, Oracle Fusion Middleware, Oracle E-business Suite application, FLEXICUBE, PeopleSoft Enterprise People Tools, JD Edwards Enterprise One, JD Edwards OneWorld Tools etc. Interestingly all these patches are cumulative in nature, therefore if you have missed out on any earlier patch implementation, you need not worry as you will get it updated with this patch
-
Risk Matrix: the critical patch update also provides you with a detailed risk matrix of the vulnerabilities that were currently fixed by these patches. Although details of security analysis done by Oracle are not provided, the information that is available can help you conduct your own risk analysis
Oracle recommends that all businesses should apply these critical patch updates immediately. Where they might have skipped one update, it is important to ensure that it does not remain skipped. Moreover, in some cases Oracle solutions may depend on other products and therefore these updates should be such as they would protect these other products as well.