int(4599)

Vulnerability Bulletins


Oracle publica parche acumulativo de Abril 2009

Vulnerability classification

Property Value
Confidence level Oficial
Impact Aumento de privilegios
Dificulty Experto
Required attacker level Acceso remoto con cuenta

System information

Property Value
Affected manufacturer Comercial Software
Affected software Oracle Database 11g, versión 11.1.0.6, 11.1.0.7
Oracle Database 10g Release 2, versiones 10.2.0.3, 10.2.0.4
Oracle Database 10g, versión 10.1.0.5
Oracle Database 9i Release 2, versiones 9.2.0.8, 9.2.0.8DV
Oracle Application Server 10g Release 2 (10.1.2), versión 10.1.2.3.0
Oracle Outside In SDK HTML Export 8.2.2, 8.3.0
Oracle XML Publisher 5.6.2, 10.1.3.2, 10.1.3.2.1
Oracle BI Publisher 10.1.3.3.0 10.1.3.3.1, 10.1.3.3.2, 10.1.3.3.3, 10.1.3.4
Oracle E-Business Suite Release 12, versión 12.0.6
Oracle E-Business Suite Release 11i, versión 11.5.10.2
PeopleSoft Enterprise PeopleTools versiones: 8.49
PeopleSoft Enterprise HRMS versiones: 8.9 y 9.0
Oracle WebLogic Server 10.3
Oracle WebLogic Server 9.0 GA, 9.1 GA, 9.2 through 9.2 MP3
Oracle WebLogic Server 8.1 through 8.1 SP6
Oracle WebLogic Server 7.0 through 7.0 SP7
Oracle WebLogic Portal 8.1 through 8.1 SP6
Oracle Data Service Integrator 10.3.0 y Oracle AquaLogic Data Services Platform (BEA ALDSP) 3.2, 3.0.1, 3.0
Oracle JRockit (formerly BEA JRockit) R27.6.2 (JDK/JRE 6, 5, 1.4.2)

Description

Se ha publicado el parche acumulativo de Abril de 2009 para los siguientes productos de Oracle: Oracle Database, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite, Oracle PeopleSoft Enterprise PeopleTools y BEA.

Este parche soluciona múltiples vulnerabilidades que pueden comprometer la integridad, confidencialidad y disponibilidad de dichos productos asi como la información manejada por ellos.

Solution



Actualización de software

Oracle
Ver tabla de actualizaciones en:
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html

Standar resources

Property Value
CVE CVE-2009-0979
CVE-2009-0985
CVE-2009-0972
CVE-2009-0977
CVE-2009-0992
CVE-2009-0984
CVE-2009-0980
CVE-2009-0975
CVE-2009-0976
CVE-2009-0978
CVE-2009-0986
CVE-2009-0973
CVE-2009-0991
CVE-2009-0981
CVE-2009-0997
CVE-2009-0988
BID

Other resources

Oracle Critical Patch Update - Abril 2009
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html

Version history

Version Comments Date
1.0 Aviso emitido 2009-04-15