Oracle rushes to patch serious flaw
The software giant has patched a flaw given its most severe vulnerability rating, after issuing an advisory on it last week.


Oracle late yesterday issued a rare out-of-cycle patch for a public flaw in its application server products that can be exploited remotely, without authentication.
The emergency patch replaces workarounds the vendor issued last week in a rare security warning about a vulnerability in the Apache plug-in for the application servers, Oracle WebLogic (formerly BEA WebLogic) Server and Express products.
Oracle advised administrators to apply the patch immediately, which replaces the vulnerable Apache plug-in with an updated version "to remedy this issue without the use of workarounds," it said.
The warning said that the flaw could be exploited remotely "over a network without the need for a username and password," compromising "the confidentiality, integrity and availability of the targeted system".
Accordingly the flaw was rated 10 on the Common Vulnerability Scoring System (CVSS) the risk evaluation framework's most severe rating.
This is the first time in three years, since Oracle began patching its systems in a regular quarterly update cycle, it has issued a security warning and patch outside its normal patch cycle.
The last Critical Patch Update Oracle issued was mid-July, but none of the flaws fixed then were as severe as this most recent Apache plug-in vulnerability.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
A 25-year veteran enterprise technology expert, Miya Knights applies her deep understanding of technology gained through her journalism career to both her role as a consultant and as director at Retail Technology Magazine, which she helped shape over the past 17 years. Miya was educated at Oxford University, earning a master’s degree in English.
Her role as a journalist has seen her write for many of the leading technology publishers in the UK such as ITPro, TechWeekEurope, CIO UK, Computer Weekly, and also a number of national newspapers including The Times, Independent, and Financial Times.
-
Organizations shift away from Oracle Java as pricing changes bite
News A survey from Azul Systems finds that, along with cost, customers cite a preference for open source and the threat of a Java usage audit
By Emma Woollacott
-
Why Java 17 growth is ‘exploding’
News Java 17 is now the most popular LTS version, according to application data from New Relic, but what's driving this growth?
By Steve Ranger
-
SuiteWorld 2023: NetSuite's day-two announcements
Live Blog Keep up-to-date with all the day-two announcements from NetSuite SuiteWorld 2023
By Rory Bathgate
-
Microsoft defends “negligent” security approach that prolonged vulnerability fix for five months
News The tech giant has refuted claims that its practices have left customers “in the dark”
By Ross Kelly
-
Ubuntu shifts to four-week update cycle
News Critical fixes will also come every two weeks, mitigating the issues involved with releasing prompt patches on the old three-week cadence
By Richard Speed
-
Can Oracle really be Linux's knight in shining armor?
Opinion The self-proclaimed champion of open source freedom would like you to forget about its history
By Richard Speed
-
Microsoft angers admins as April Patch Tuesday delivers password feature without migration guidance
News Security fixes include a zero day exploited by a ransomware group and seven critical flaws
By Connor Jones
-
Oracle’s Java subscription changes spark concerns over cost hikes for smaller businesses
News Smaller businesses could incur significant cost hikes as high as 1,400% with most new customers expected to pay at least double
By Ross Kelly