int(3114)

Vulnerability Bulletins


Oracle publica parche acumulativo de Abril 2007

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio exotico

System information

Property Value
Affected manufacturer Comercial Software
Affected software Oracle Database 10g Release 2, versions 10.2.0.2, 10.2.0.3
Oracle Database 10g Release 1, versions 10.1.0.4, 10.1.0.5
Oracle Database 10g Release 2, version 10.2.0.1
Oracle9i Database Release 2, versions 9.2.0.7, 9.2.0.8
Oracle9i Database Release 1, versions 9.0.1.5, 9.0.1.5 FIPS
Oracle9i Database Release 2, versions 9.2.0.5
Oracle Secure Enterprise Search 10g Release 1, version 10.1.6
Oracle Application Server 10g Release 3 (10.1.3), versions 10.1.3.0.0, 10.1.3.1.0, 10.1.3.2.0
Oracle Application Server 10g Release 2 (10.1.2), versions 10.1.2.0.1 - 10.1.2.0.2, 10.1.2.1.0, 10.1.2.2.0
Oracle Application Server 10g (9.0.4), version 9.0.4.3
Oracle10g Collaboration Suite Release 1, version 10.1.2
Oracle E-Business Suite Release 11i, versions 11.5.7 - 11.5.10 CU2
Oracle E-Business Suite Release 12, version 12.0.0
Oracle Enterprise Manager 9i Release 2, versions 9.2.0.7, 9.2.0.8
Oracle Enterprise Manager 9i, version 9.0.1.5
Oracle PeopleSoft Enterprise PeopleTools versions 8.22, 8.47, 8.48
Oracle PeopleSoft Enterprise Human Capital Management version 8.9
JD Edwards EnterpriseOne Tools version 8.96
JD Edwards OneWorld Tools SP23

Description

Se ha publicado el parche acumulativo de Abril de 2007 para los siguientes productos de Oracle: Oracle Database Server, Oracle Application Server, Oracle Identity Management, Oracle E-Business Suite, Oracle PeopleSoft Enterprise PeopleTools, Oracle Enterprise Manager.

Este parche soluciona múltiples vulnerabilidades que pueden comprometer la integridad, confidencialidad y disponibilidad de dichos productos así como la información manejada por ellos.

Solution



Actualización de software

Oracle
Oracle Database
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=420061.1#DBAVAIL
Oracle Application Server
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=420061.1#ASMIDTIER
Oracle Collaboration Suite
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=420061.1#OCSAVAIL
Oracle E-Business Suite y Applications
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=420072.1
Oracle Enterprise Manager
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=420061.1#DBAVAIL
Oracle PeopleSoft Enterprise y JD Edwards EnterpriseOne
http://www.peoplesoft.com/corp/en/support/security_index.jsp

Standar resources

Property Value
CVE
BID

Other resources

Oracle Critical Patch Update - April 2007
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html

Version history

Version Comments Date
1.0 Aviso emitido 2007-04-18
Ministerio de Defensa
CNI
CCN
CCN-CERT