FYI…

Oracle CPU Announcement - Jan 2015
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
Jan 20, 2015 - "… Oracle has received specific reports of malicious exploitation of vulnerabilities for which Oracle has already released fixes. In some instances, it has been reported that malicious attackers have been successful because customers had failed to apply these Oracle patches. Oracle therefore strongly recommends that customers remain on actively-supported versions and apply Critical Patch Update fixes without delay. This Critical Patch Update contains -169- new security fixes across the product families…"

- https://blogs.oracle.com/security/entry/january_2015_critical_patch_update
Jan 20, 2015 - "… Out of these 169 vulnerabilities, 8 are for the Oracle Database. None of these database vulnerabilities are remotely exploitable without authentication, but a number of these vulnerabilities are relatively severe… Because of the severity of these issues, Oracle highly recommends that this Critical Patch Update be applied against affected systems as soon as possible… Organizations should disable the use of all versions of SSL as they can no longer rely on SSL to ensure secure communications between systems. Customers should update their custom code to switch to a more resilient protocol (e.g., TLS 1.2). They should also expect that all versions of SSL be disabled in all Oracle software moving forward. A manual configuration change can allow Java SE clients and server endpoints, which have been updated with this Critical Patch Update, to continue to temporarily use SSL v3.0. However, Oracle strongly recommends organizations to phase out their use of SSL v3.0 as soon as possible…"

- https://www.us-cert.gov/ncas/current-activity/2015/01/20/Oracle-Releases-January-2015-Security-Advisory
Jan 20, 2015 - "Oracle has released its critical Patch Update for January 2015 to address 169 vulnerabilities across multiple products.
This update contains the following security fixes:
• 8 for Oracle Database Server
• 36 for Oracle Fusion Middleware
• 10 for Oracle Enterprise Manager Grid Control
• 10 for Oracle E-Business Suite
• 6 for Oracle Supply Chain Products Suite
• 7 for Oracle PeopleSoft Products
• 1 for Oracle JD Edwards Products
• 17 for Oracle Siebel CRM
• 2 for Oracle iLearning
• 2 for Oracle Communications Applications
• 1 for Oracle Retail Applications
• 1 for Oracle Health Sciences Applications
• 19 for Oracle Java SE
• 29 for Oracle Sun Systems Products Suite
• 11 for Oracle Linux and Virtualization
• 9 for Oracle MySQL …"

Patch Availability Table
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html#PIN

Third Party Bulletin - Risk Matrix
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
"… This Third Party Bulletin contains 8 new security fixes for the Oracle Solaris. 5 of these vulnerabilities may be remotely exploitable without authentication…"
- http://www.oracle.com/technetwork/topics/security/public-vuln-to-advisory-mapping-093627.html
 

:ph34r: :ph34r: