SHARE
Facebook X Pinterest WhatsApp

Major Oracle Patch Covers Enterprise Products, Database Server

Oracle has released a set of 49 patches that addresses new flaws in multiple versions of its Database Server, Application Server, Collaboration Suite, E-Business and Applications, and Enterprise Manager products. The patches are available on OTN (the Oracle Technology Network). The product flaws vary in terms of exploitability. Oracle Database has 12 flaws, including a […]

Written By
thumbnail Lisa Vaas
Lisa Vaas
Jul 12, 2005
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Oracle has released a set of 49 patches that addresses new flaws in multiple versions of its Database Server, Application Server, Collaboration Suite, E-Business and Applications, and Enterprise Manager products.

The patches are available on OTN (the Oracle Technology Network).

The product flaws vary in terms of exploitability. Oracle Database has 12 flaws, including a flaw in Database 10g’s Oracle OLAP (online analytical processing) that requires Database privilege—execute on olapsys—but which, according to Oracle’s posting, is both easily accessible and would have a wide impact.

Oracle’s Application Server also has a dozen flaws that span the range in terms of authorization required, severity of impact and ease of exploitation. Collaboration Suite has six flaws and E-Business Suite has 17, while Enterprise Manager has two.

The new database vulnerabilities addressed by this Critical Patch Update don’t affect Oracle Database Client-only installations (installations that don’t have the Oracle Database Server installed).

Therefore, according to Oracle’s posting, it is not necessary to apply this Critical Patch Update to client-only installations if a prior Critical Patch Update, or Alert 68, has already been applied to the client-only installations.

Oracle issues a fix for a previous patch that has been determined to be faulty. Click here to read more.

The Oracle Database Server, Enterprise Manager and Oracle Application Server patches are cumulative, containing all fixes from the previous Critical Patch Update.

Not so for E-Business Suite or Collaboration Suite patches, however, so customers using these products should refer to previous Critical Patch Updates to identify previous fixes they need to apply.

This is the third of Oracle’s Critical Patch Updates since the company started cumulative patch releases in January.

Jon Oltsik, an analyst at Enterprise Strategy Group, said that Oracle customers are mostly comfortable with Oracle’s new patching strategy, but they would like Oracle to be more proactive with emergency patches.

“If any are high impact, if I were a customer and had a major investment in Oracle, I wouldn’t want to wait around for the cumulative patch release,” he said. “I want to know about them immediately and apply them immediately.”

Read more here about Oracle’s move to a quarterly patch cycle.

In contrast, Microsoft offers custom services for big enterprise customers. Oracle has resisted that, Oltsik said, since it’s more difficult from a process perspective to offer such services. “[But] if I’m a big customer, I don’t care about your processes,” he said. “If I’m buying from you, give me good service.”

“People tend to criticize Microsoft from [the standpoint of] general security and number of vulnerabilities,” Oltsik said. “But from [the perspective of] patching and management strategies, they’re very, very good and flexible. I’d say, more so than Oracle.”

Check out eWEEK.com’s for the latest database news, reviews and analysis.

Recommended for you...

Manny Rivelo on Evolving Channel & How MSPs Can Get Ahead
Victoria Durgin
Aug 20, 2025
Databricks Raises at $100B+ Valuation on AI Momentum
Allison Francis
Aug 20, 2025
Keepit Achieves SOC 2 Type 1 & Canadian Ingram Micro Deal
Jordan Smith
Aug 20, 2025
AI Customer Service Fails to Satisfy Consumer Needs: Verizon
Franklin Okeke
Aug 19, 2025
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.