Oracle April 2019 Critical Patch Update for All Product Families Threat Alert

Oracle April 2019 Critical Patch Update for All Product Families Threat Alert

April 30, 2019 | Adeline Zhang

Overview

On April 16, 2019, local time, Oracle released its security advisory of the Critical Patch Update (CPU) for the second quarter. The CPU fixes 297 vulnerabilities of varying severity levels across the product families. For details about affected products and available patches, visit the following link:

https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html

Vulnerabilities

Product Number of Vulnerabilities Number of Remote Exploits Without Auth. CVSS Base Score
Oracle Database server 6 1 9.1
Oracle Berkeley DB 1 0 3.3
Oracle Commerce 3 3 6.5
Oracle Communications Applications 26 19 9.8
Oracle Construction and Engineering Suite 8 7 9.8
Oracle E-Business Suite 35 33 8.2
Oracle Enterprise Manager Products Suite 11 7 9.8
Oracle Financial Services Applications 14 13 9.8
Oracle Food and Beverage Applications 1 1 6.1
Oracle Fusion Middleware 53 42 9.8
Oracle Health Sciences Applications 2 1 9.8
Oracle Hospitality Applications 5 5 9.8
Oracle Java SE 5 5 9.0
Oracle JD Edwards Products 8 7 9.8
Oracle MySQL 45 4 6.5
Oracle PeopleSoft Products 12 8 8.7
Oracle Retail Applications 24 20 9.8
Oracle Siebel CRM 8 6 9.8
Oracle Sun Systems Products Suite 3 2 5.3
Oracle Supply Chain Products Suite 5 5 9.8
Oracle Support Tools 1 1 6.1
Oracle Utilities Applications 6 5 9.8
Oracle Virtualization 15 3 9.8

Affected Products and Versions

For details, see the appendix.

Critical Patch Update

A Critical Patch Update is a collection of patches for multiple security vulnerabilities. Critical Patch Update patches are usually cumulative, but each advisory describes only the security fixes added since the previous Critical Patch Update advisory. Thus, prior Critical Patch Update advisories should be reviewed for information regarding earlier published security fixes.

Solution

Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Patch Update fixes as soon as possible.

Appendix

The following table lists affected products (and their versions) and related patches.

Affected Products and Versions Patch Availability Document
Agile Recipe Management for Pharmaceuticals, versions 9.3.3, 9.3.4 Oracle Supply Chain Products
Enterprise Manager Base Platform, versions 12.1.0.5.0, 13.2.0.0.0, 13.3.0.0.0 Enterprise Manager
Enterprise Manager Ops Center, version 12.3.3 Enterprise Manager
FMW Platform, version 12.2.1.3.0 Fusion Middleware
Instantis EnterpriseTrack, versions 17.1, 17.2, 17.3 Oracle Construction and Engineering Suite
JD Edwards EnterpriseOne Tools, version 9.2 JD Edwards
JD Edwards World Technical Foundation, versions A9.2, A9.3.1, A9.4 JD Edwards
MICROS Lucas, versions 2.9.5.6, 2.9.5.7 Retail Applications
MICROS Relate CRM Software, version 11.4 Retail Applications
MICROS Retail-J, version 12.1.2 Retail Applications
MySQL Connectors, versions 5.3.12 and prior, 8.0.15 and prior MySQL
MySQL Enterprise Backup, versions 3.12.3 and prior, 4.1.2 and prior MySQL
MySQL Enterprise Monitor, versions 4.0.8 and prior, 8.0.14 and prior MySQL
MySQL Server, versions 5.6.43 and prior, 5.7.25 and prior, 8.0.15 and prior MySQL
Oracle Agile PLM, versions 9.3.3, 9.3.4, 9.3.5 Oracle Supply Chain Products
Oracle API Gateway, version 11.1.2.4.0 Fusion Middleware
Oracle Application Testing Suite, version 13.3.0.1 Enterprise Manager
Oracle AutoVue 3D Professional Advanced, versions 21.0.0, 21.0.1 Oracle Supply Chain Products
Oracle Banking Platform, versions 2.4.0, 2.4.1, 2.5.0, 2.6.0 Oracle Banking Platform
Oracle Berkeley DB, versions prior to 6.138, prior to 18.1.32 Berkeley DB
Oracle BI Publisher, versions 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0 Fusion Middleware
Oracle Business Intelligence Enterprise Edition, versions 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0 Fusion Middleware
Oracle Business Process Management Suite, versions 11.1.1.9.0, 12.1.3.0.0, 12.2.1.3.0 Fusion Middleware
Oracle Business Transaction Management, version 12.1.0 Enterprise Manager
Oracle Commerce Merchandising, version 11.2.0.3 Oracle Commerce
Oracle Commerce Platform, versions 11.2.0.3, 11.3.1 Oracle Commerce
Oracle Communications Application Session Controller, versions 3.7.1, 3.8.0 Oracle Communications Application Session Controller
Oracle Communications EAGLE Application Processor, versions 16.1.0, 16.2.0 Oracle Communications EAGLE Application Processor
Oracle Communications EAGLE LNP Application Processor, versions 10.0, 10.1, 10.2 Oracle Communications EAGLE LNP Application Processor
Oracle Communications Instant Messaging Server, version 10.0.1 Oracle Communications Instant Messaging Server
Oracle Communications Interactive Session Recorder, versions 6.0, 6.1, 6.2 Oracle Communications Interactive Session Recorder
Oracle Communications LSMS, versions 13.1, 13.2, 13.3 Oracle Communications LSMS
Oracle Communications Messaging Server, versions 8.0, 8.1 Oracle Communications Messaging Server
Oracle Communications Operations Monitor, versions 3.4, 4.0 Oracle Communications Operations Monitor
Oracle Communications Policy Management, versions 12.1, 12.2, 12.3, 12.4 Oracle Communications Policy Management
Oracle Communications Pricing Design Center, versions 11.1, 12.0 Oracle Communications Pricing Design Center
Oracle Communications Service Broker, version 6.0 Oracle Communications Service Broker
Oracle Communications Service Broker Engineered System Edition, version 6.0 Oracle Communications Service Broker Engineered System Edition
Oracle Communications Session Border Controller, versions 8.0.0, 8.1.0, 8.2.0 Oracle Communications Session Border Controller
Oracle Communications Unified Inventory Management, versions 7.3.2, 7.3.4, 7.3.5, 7.4.0 Oracle Communications Unified Inventory Management
Oracle Configuration Manager, version 12.1.0 Enterprise Manager
Oracle Configurator, versions 12.1, 12.2 Oracle Supply Chain Products
Oracle Data Integrator, versions 11.1.1.9.0, 12.2.1.3.0 Fusion Middleware
Oracle Database Server, versions 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c, 19c Database
Oracle E-Business Suite, versions 0.9.8, 1.0.0, 1.0.1, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8 E-Business Suite
Oracle Endeca Information Discovery Integrator, version 3.2.0 Fusion Middleware
Oracle Enterprise Communications Broker, versions 3.0.0, 3.1.0 Oracle Enterprise Communications Broker
Oracle Enterprise Operations Monitor, versions 3.4, 4.0 Oracle Enterprise Operations Monitor
Oracle Enterprise Session Border Controller, versions 8.0.0, 8.1.0, 8.2.0 Oracle Enterprise Session Border Controller
Oracle Financial Services Analytical Applications Infrastructure, versions 7.3.3 – 7.3.5, 8.0.0 – 8.0.7 Oracle Financial Services Analytical Applications Infrastructure
Oracle Financial Services Asset Liability Management, versions 8.0.4 – 8.0.7 Oracle Financial Services Asset Liability Management
Oracle Financial Services Data Integration Hub, versions 8.0.5 – 8.0.7 Oracle Financial Services Data Integration Hub
Oracle Financial Services Funds Transfer Pricing, versions 8.0.4 – 8.0.7 Oracle Financial Services Funds Transfer Pricing
Oracle Financial Services Hedge Management and IFRS Valuations, versions 8.0.4 – 8.0.7 Oracle Financial Services Hedge Management and IFRS Valuations
Oracle Financial Services Liquidity Risk Management, versions 8.0.2 – 8.0.6 Oracle Financial Services Liquidity Risk Management
Oracle Financial Services Loan Loss Forecasting and Provisioning, versions 8.0.2 – 8.0.7 Oracle Financial Services Loan Loss Forecasting and Provisioning
Oracle Financial Services Market Risk Measurement and Management, versions 8.0.5, 8.0.6 Oracle Financial Services Market Risk Measurement and Management
Oracle Financial Services Profitability Management, versions 8.0.4 – 8.0.6 Oracle Financial Services Profitability Management
Oracle Financial Services Reconciliation Framework, versions 8.0.5, 8.0.6 Oracle Financial Services Analytical Applications Reconciliation Framework
Oracle FLEXCUBE Private Banking, versions 2.0.0.0, 2.2.0.1, 12.0.1.0, 12.0.3.0, 12.1.0.0 Oracle Financial Services Applications
Oracle Fusion Middleware MapViewer, version 12.2.1.3.0 Fusion Middleware
Oracle Health Sciences Data Management Workbench, version 2.4.8 Health Sciences
Oracle Healthcare Master Person Index, versions 3.0, 4.0 Health Sciences
Oracle Hospitality Cruise Dining Room Management, version 8.0.80 Oracle Hospitality Cruise Dining Room Management
Oracle Hospitality Cruise Fleet Management, version 9.0.11 Oracle Hospitality Cruise Fleet Management
Oracle Hospitality Guest Access, versions 4.2.0, 4.2.1 Oracle Hospitality Guest Access
Oracle Hospitality Reporting and Analytics, version 9.1.0 Oracle Hospitality Reporting and Analytics
Oracle HTTP Server, version 12.2.1.3.0 Fusion Middleware
Oracle Identity Analytics, version 11.1.1.5.8 Fusion Middleware
Oracle Java SE, versions 7u211, 8u202, 11.0.2, 12 Java SE
Oracle Java SE Embedded, version 8u201 Java SE
Oracle JDeveloper, versions 11.1.1.9.0, 12.1.3.0.0, 12.2.1.3.0 Fusion Middleware
Oracle Knowledge, versions 8.5.1.0 – 8.5.1.7, 8.6.0, 8.6.1 Oracle Knowledge
Oracle Managed File Transfer, versions 12.1.3.0.0, 12.2.1.3.0 Fusion Middleware
Oracle Outside In Technology, versions 8.5.3, 8.5.4 Fusion Middleware
Oracle Real-Time Scheduler, version 2.3.0 Oracle Utilities Applications
Oracle Retail Allocation, version 15.0.2 Retail Applications
Oracle Retail Convenience Store Back Office, version 3.6 Retail Applications
Oracle Retail Customer Engagement, versions 16.0, 17.0 Retail Applications
Oracle Retail Customer Management and Segmentation Foundation, versions 16.0, 17.0, 18.0 Retail Applications
Oracle Retail Invoice Matching, versions 12.0, 13.0, 13.1, 13.2, 14.0, 14.1, 15.0 Retail Applications
Oracle Retail Merchandising System, versions 15.0, 16.0 Retail Applications
Oracle Retail Order Broker, versions 5.1, 5.2, 15.0, 16.0 Retail Applications
Oracle Retail Point-of-Service, versions 13.4, 14.0, 14.1 Retail Applications
Oracle Retail Workforce Management Software, version 1.60.9.0.0 Retail Applications
Oracle Retail Xstore Point of Service, versions 7.0, 7.1 Retail Applications
Oracle Secure Global Desktop, version 5.4 Virtualization
Oracle Service Bus, versions 11.1.1.9.0, 12.1.3.0.0, 12.2.1.3.0 Fusion Middleware
Oracle SOA Suite, versions 11.1.1.9.0, 12.1.3.0.0, 12.2.1.3.0 Fusion Middleware
Oracle Solaris, versions 10, 11 Systems
Oracle Traffic Director, version 11.1.1.9.0 Fusion Middleware
Oracle Transportation Management, versions 6.3.7, 6.4.2, 6.4.3 Oracle Supply Chain Products
Oracle Tuxedo, version 12.1.1.0.0 Fusion Middleware
Oracle Utilities Framework, versions 2.2.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.2.0, 4.3.0.3.0, 4.3.0.4.0, 4.3.0.5.0, 4.3.0.6.0, 4.4.0.0.0 Oracle Utilities Applications
Oracle Utilities Mobile Workforce Management, version 2.3.0 Oracle Utilities Applications
Oracle Utilities Network Management System, version 1.12.0.3 Oracle Utilities Applications
Oracle VM VirtualBox, versions prior to 5.2.28, prior to 6.0.6 Virtualization
Oracle WebCenter Portal, version 12.2.1.3.0 Fusion Middleware
Oracle WebCenter Sites, version 12.2.1.3.0 Fusion Middleware
Oracle WebLogic Server, versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 Fusion Middleware
OSS Support Tools, version 19.1 Support Tools
PeopleSoft Enterprise ELM, version 9.2 PeopleSoft
PeopleSoft Enterprise ELM Enterprise Learning Management, version 9.2 PeopleSoft
PeopleSoft Enterprise HCM Talent Acquisition Manager, version 9.2 PeopleSoft
PeopleSoft Enterprise HRMS, version 9.2 PeopleSoft
PeopleSoft Enterprise PeopleTools, versions 8.55, 8.56, 8.57 PeopleSoft
PeopleSoft Enterprise PT PeopleTools, versions 8.55, 8.56, 8.57 PeopleSoft
Primavera P6 Enterprise Project Portfolio Management, versions 8.4, 15.1, 15.2, 16.1, 16.2, 17.7 – 17.12, 18.8 Oracle Construction and Engineering Suite
Primavera Unifier, versions 16.1, 16.2, 17.7 – 17.12, 18.8 Oracle Construction and Engineering Suite
Siebel Applications, version 19.3 Siebel

 

Statement

This advisory is only used to describe a potential risk. NSFOCUS does not provide any commitment or promise on this advisory. NSFOCUS and the author will not bear any liability for any direct and/or indirect consequences and losses caused by transmitting and/or using this advisory. NSFOCUS reserves all the rights to modify and interpret this advisory. Please include this statement paragraph when reproducing or transferring this advisory. Do not modify this advisory, add/delete any information to/from it, or use this advisory for commercial purposes without permission from NSFOCUS.

About NSFOCUS

NSFOCUS IB is a wholly owned subsidiary of NSFOCUS, an enterprise application and network security provider, with operations in the Americas, Europe, the Middle East, Southeast Asia and Japan. NSFOCUS IB has a proven track record of combatting the increasingly complex cyber threat landscape through the construction and implementation of multi-layered defense systems. The company’s Intelligent Hybrid Security strategy utilizes both cloud and on-premises security platforms, built on a foundation of real-time global threat intelligence, to provide unified, multi-layer protection from advanced cyber threats.

For more information about NSFOCUS, please visit:

https://www.nsfocusglobal.com.

NSFOCUS, NSFOCUS IB, and NSFOCUS, INC. are trademarks or registered trademarks of NSFOCUS, Inc. All other names and trademarks are property of their respective firms.