The buffer overflow vulnerability affects all supported versions of Oracle database servers and could enable a remote attacker to compromise the data Oracle released a patch for a recently-discovered ...
Attackers can execute arbitrary code without authentication if Oracle's Identity or Web Services Managers are exposed to the Web.
Oracle released 41 security fixes for its flagship database and several other products Tuesday, including 15 patches for vulnerabilities that can be exploited remotely without a username or password.
The disclosure follows reports that the cybercriminal group Clop has been extorting a significant number of E-Business Suite customers. Oracle is now linking a widespread data extortion campaign ...
Oracle probably worried some DBAs earlier this week when it released its Critical Patch Update, but neglected to patch its most critical database flaw of the quarter for 9.2.0.8 users on the Windows ...