Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Oracle Issues Emergency Security Advisory

In a rare move, Oracle broke its normal procedures and issued an emergency patch due to concerns about the impact of a successful attack.

The fix addresses a denial-of-service vulnerability in Oracle’s Apache Web server software. According to Oracle, the issue affects multiple versions of Oracle Fusion Middleware 11g Release 1, Oracle Application Server 10g Release 3 and Oracle Application Server 10g Release 2.

In a rare move, Oracle broke its normal procedures and issued an emergency patch due to concerns about the impact of a successful attack.

The fix addresses a denial-of-service vulnerability in Oracle’s Apache Web server software. According to Oracle, the issue affects multiple versions of Oracle Fusion Middleware 11g Release 1, Oracle Application Server 10g Release 3 and Oracle Application Server 10g Release 2.

“This security alert addresses the security issue CVE-2011-3192, a denial of service vulnerability in Apache HTTPD, which is applicable to Oracle HTTP Server products based on Apache 2.0 or 2.2,” the company wrote in an advisory. “This vulnerability may be remotely exploitable without authentication, i.e. it may be exploited over a network without the need for a username and password. A remote user can exploit this vulnerability to impact the availability of un-patched systems.”

This is just the fifth time Oracle has released an out-of-band patch since starting its Patch Tuesday cycle in 2005, blogged Paul Ducklin, Sophos’ head of technology for Asia Pacific.

“The vulnerability, CVE-2011-3192, allowed even a single web client to trigger a huge number of simultaneous requests for large amounts of data,” he explained. “The flaw was exploited by sending a request for multiple parts of the same file at the same time.”’

The Apache Software Foundation has already issued two patches for the vulnerability. The first, version 2.2.20, was actually released at the end of August. It was followed by version 2.2.21, which was released recently. It is unclear from the Oracle advisory which of the patches Oracle used in its update. Information about version 2.2.21 however can be found here.

Advertisement. Scroll to continue reading.

“However conservative you might be, if you’re an Oracle user, this patch is definitely recommended in a hurry,” Ducklin wrote. “The general unwillingness of Oracle to deviate from its once-every-three-months patch cycle spells one word, “Importance.””

Written By

Marketing professional with a background in journalism and a focus on IT security.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.