Oracle: Unpatched Versions of WebLogic App Server Under Active Attack

CVE-2020-2883 was patched in Oracle’s April 2020 Critical Patch Update – but proof of concept exploit code was published shortly after. Continue reading Oracle: Unpatched Versions of WebLogic App Server Under Active Attack

Oracle E-Business Suite Flaw Allows Downloads of Documents

Oracle today in its Critical Patch Update addressed a critical vulnerability in its Oracle E-Business Suite of business applications that allows for the download of business documents. Continue reading Oracle E-Business Suite Flaw Allows Downloads of Documents

Record Oracle Patch Update Addresses ShadowBrokers, Struts 2 Vulnerabilities

Oracle released a record 299 patches, including a fix for a Solaris vulnerability disclosed by the ShadowBrokers, and another for the recently disclosed Apache Struts 2 flaw. Continue reading Record Oracle Patch Update Addresses ShadowBrokers, Struts 2 Vulnerabilities