RETIRED: Oracle January 2010 Critical Patch Update Multiple Vulnerabilities

BID:37668

Info

RETIRED: Oracle January 2010 Critical Patch Update Multiple Vulnerabilities

Bugtraq ID: 37668
Class: Unknown
CVE:
Remote: Yes
Local: Yes
Published: Jan 07 2010 12:00AM
Updated: Jan 12 2010 11:11PM
Credit: Oracle
Vulnerable: Oracle Weblogic Server 10.3.1
Oracle Weblogic Server 9.2 MP3
Oracle Weblogic Server 9.2 MP2
Oracle Weblogic Server 9.2 MP1
Oracle Weblogic Server 9.2
Oracle Weblogic Server 9.1 GA
Oracle Weblogic Server 9.0 GA
Oracle Weblogic Server 8.1 SP6
Oracle Weblogic Server 8.1 MP6
Oracle Weblogic Server 8.1 MP4
Oracle Weblogic Server 8.1
Oracle Weblogic Server 7.0 SP7
Oracle Weblogic Server 7.0 MP5
Oracle Weblogic Server 7.0 MP4
Oracle Weblogic Server 7.0 MP2
Oracle Weblogic Server 7.0
Oracle Weblogic Server 10.3
Oracle Weblogic Server 10.0 MP2
Oracle Weblogic Server 10.0 MP1
Oracle Weblogic Server 10
Oracle Primavera P6 Web Services 6.2.1
Oracle Primavera P6 Web Services 7.0 SP
Oracle Primavera P6 Web Services 7.0
Oracle Primavera P6 Enterprise Project Portfolio Management 6.2.1
Oracle Primavera P6 Enterprise Project Portfolio Management 7.0
Oracle Primavera P6 Enterprise Project Portfolio Management 6.1
Oracle PeopleSoft Enterprise Human Capital Management 9.0
Oracle PeopleSoft Enterprise Human Capital Management 8.9
Oracle Oracle9i Standard Edition 9.2 .8DV
Oracle Oracle9i Standard Edition 9.2 .8
Oracle Oracle9i Personal Edition 9.2 .8DV
Oracle Oracle9i Personal Edition 9.2 .8
Oracle Oracle9i Enterprise Edition 9.2 .8DV
Oracle Oracle9i Enterprise Edition 9.2 .8.0
Oracle Oracle11g Standard Edition 11.1 .7
Oracle Oracle10g Standard Edition 10.2 .3
Oracle Oracle10g Standard Edition 10.1 .5
Oracle Oracle10g Standard Edition 10.2.0.4
Oracle Oracle10g Personal Edition 10.2 .3
Oracle Oracle10g Personal Edition 10.1 .5
Oracle Oracle10g Personal Edition 10.2.0.4
Oracle Oracle10g Enterprise Edition 10.2 .3
Oracle Oracle10g Enterprise Edition 10.1 .5
Oracle Oracle10g Enterprise Edition 10.2.0.4
Oracle Oracle10g Application Server 10.1.3 .5.1
Oracle Oracle10g Application Server 10.1.3 .5.0
Oracle Oracle10g Application Server 10.1.3 .4.0
Oracle Oracle10g Application Server 10.1.2.3.0
Oracle JRockit R27.6.5
Oracle JRockit R27.6.4
Oracle JRockit R27.6.3
Oracle JRockit R27.6.2
Oracle JRockit R27.6.0-50 1.5.0 15
Oracle JRockit R27.6.0
Oracle JRockit R27.1.0
Oracle E-Business Suite 12 12.1.2
Oracle E-Business Suite 12 12.1.1
Oracle E-Business Suite 12 12.0.5
Oracle E-Business Suite 12 12.0.4
Oracle E-Business Suite 11i 11.5.10.2
Oracle E-Business Suite 12.0.6
Oracle Access Manager 10.1.4 .2
Oracle Access Manager 7.0.4 .3
Not Vulnerable:

Discussion

RETIRED: Oracle January 2010 Critical Patch Update Multiple Vulnerabilities

Oracle has released advance notification regarding the January 2010 critical patch update to be released on January 12, 2010. The update addresses 24 vulnerabilities affecting the following software:

Oracle Database
Oracle Application Server
Oracle E-Business Suite and Applications Executive
PeopleSoft Enterprise and JD Edwards EnterpriseOne Executive
Oracle BEA Products
Oracle Primavera Product Suite

NOTE: This BID is being retired; the following individual records exist to better document these issues:

37744 Oracle Application Server CVE-2010-0070 Remote Oracle Containers for J2EE Vulnerability
37740 Oracle Database CVE-2009-1996 Remote Logical Standby Vulnerability
37735 Oracle Application Express CVE-2010-0076 Remote Application Express Application Builder Vulnerability
37748 Oracle WebLogic Server CVE-2010-0068 Remote WebLogic Server Vulnerability
37746 Oracle Database CVE-2009-3410 Remote RDBMS Vulnerability
37743 Oracle Database CVE-2009-3411 Remote Oracle Data Pump Vulnerability
37750 Oracle Application Server CVE-2010-0067 Remote Oracle Containers for J2EE Vulnerability
37732 Oracle PeopleSoft Enterprise HCM CVE-2010-0080 Remote eProfile Vulnerability
37751 Oracle WebLogic Server CVE-2010-0074 Remote Vulnerability
37745 Oracle E-Business Suite CVE-2010-0077 CRM Technical Foundation (mobile) Remote Vulnerability
37739 Oracle Application Server CVE-2010-0066 Access Manager Identity Server Remote Vulnerability
37741 Oracle WebLogic Server CVE-2010-0078 Remote WebLogic Server Vulnerability
37738 Oracle Database CVE-2009-3413 Oracle Spatial Remote Vulnerability
37736 Oracle E-Business Suite CVE-2010-0075 Remote Oracle HRMS (Self Service) Vulnerability
37737 Oracle Weblogic Server CVE-2010-0069 Unspecified Remote Vulnerability
37733 Oracle Database CVE-2010-0072 Oracle Secure Backup Remote Vulnerability
37731 Oracle Database and Application Server CVE-2009-3412 Local Unzip Vulnerability
37734 Oracle E-Business Suite CVE-2009-3416 Oracle Application Object Library Remote Vulnerability
37730 Oracle Database CVE-2009-3414 Oracle Spatial Remote Unspecified Vulnerability
37728 Oracle Database CVE-2010-0071 Remote Listener Vulnerability
37729 Oracle Database CVE-2009-3415 OLAP Remote Unspecified Vulnerability
36881 Sun Java SE November 2009 Multiple Security Vulnerabilities
35958 Sun Java Runtime Environment XML Parsing Denial of Service Vulnerability

Exploit / POC

RETIRED: Oracle January 2010 Critical Patch Update Multiple Vulnerabilities

Some of these issues may not require specific exploit code and may be trivial to exploit.

Solution / Fix

RETIRED: Oracle January 2010 Critical Patch Update Multiple Vulnerabilities

Solution:
The vendor plans to release updates to address these issues on January 12, 2010.

References

RETIRED: Oracle January 2010 Critical Patch Update Multiple Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report