Oracle July 2014 Critical Patch Update Multiple Vulnerabilities

BID:68501

Info

Oracle July 2014 Critical Patch Update Multiple Vulnerabilities

Bugtraq ID: 68501
Class: Unknown
CVE:
Remote: Yes
Local: Yes
Published: Jul 10 2014 12:00AM
Updated: Jul 10 2014 12:00AM
Credit: Oracle
Vulnerable: Oracle Weblogic Server 10.0.2
Oracle VM VirtualBox 4.1
Oracle VM VirtualBox 4.0
Oracle VM VirtualBox 3.2
Oracle VM VirtualBox 3.1
Oracle Virtual Desktop Infrastructure 3.2
Oracle PeopleSoft Enterprise SCM 9.1
Oracle PeopleSoft Enterprise PeopleTools 8.52
Oracle PeopleSoft Enterprise ELS 9.1
Oracle Glassfish Server 3.0.1
Oracle Glassfish Server 2.1.1
Oracle GlassFish Communications Server 2.0
Not Vulnerable:

Discussion

Oracle July 2014 Critical Patch Update Multiple Vulnerabilities

Oracle has released advance notification regarding the July 2014 Critical Patch Update (CPU) to be released on July 15, 2014. The update addresses 115 vulnerabilities affecting the following software:

Oracle Database 11g Release 1
Oracle Database 11g Release 2
Oracle Database 12c Release 1
Oracle Fusion Middleware 11g Release 1
Oracle Fusion Middleware 12c Release 1
Oracle Glassfish Server
Oracle Traffic Director
Oracle iPlanet Web Proxy Server
Oracle iPlanet Web Server
Oracle WebCenter Portal
Oracle WebLogic Server
Oracle JDeveloper
Oracle BI Publisher
Oracle Glassfish Communication Server
Oracle HTTP Server
Oracle Hyperion Essbase
Oracle Hyperion BI+
Oracle Hyperion Enterprise Performance Management Architect
Oracle Common Admin
Oracle Hyperion Analytic Provider Services
Oracle E-Business Suite Release 11i
Oracle E-Business Suite Release 12i
Oracle Transportation Management
Oracle Agile Product Collaboration
Oracle PeopleSoft Enterprise ELS Enterprise Learning Management
Oracle PeopleSoft Enterprise PT Tools
Oracle PeopleSoft Enterprise FIN Install
Oracle PeopleSoft Enterprise SCM Purchasing
Oracle Siebel Travel & Transportation
Oracle Siebel UI Framework
Oracle Siebel Core - Server OM Frwks
Oracle Siebel Core - EAI
Oracle Communications Messaging Server
Oracle Retail Back Office
Oracle Retail Central Office
Oracle Retail Returns Management
Primavera P6 Enterprise Project Portfolio Management
Oracle Java SE
Oracle JRockit
Oracle Solaris
Oracle Secure Global Desktop
Oracle VM VirtualBox
Oracle Virtual Desktop Infrastructure (VDI)
Sun Ray Software
Oracle MySQL Server

Exploiting the most severe of these vulnerabilities may potentially compromise the database server or the host operating system.

Exploit / POC

Oracle July 2014 Critical Patch Update Multiple Vulnerabilities

Some of these issues may not require specific exploit code and may be trivial to exploit.

Solution / Fix

References

Oracle July 2014 Critical Patch Update Multiple Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report