Oracle Security Patch Update – 16 October 2024

Oracle released its critical patch updates for October 2024, containing (334) new security patches for multiple affected products in Oracle code and third-party components.

The addressed vulnerabilities could allow the attacker to perform various attacks such as obtaining sensitive information, performing denial of service attacks, conducting cross-site scripting attacks, bypassing security restrictions, gaining elevated privileges, data manipulation (update, insert, or delete access), or executing arbitrary commands and gaining access to the affected product.

Sample of the addressed vulnerabilities:

1. Oracle WebLogic Server Code Execution Vulnerability (CVE-2024-21216):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

2. Oracle Applications Manager SQL Injection Vulnerability (CVE-2024-21268):

  • CVSS: 8.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Data Manipulation

Sample of the affected products:

  • Oracle Banking APIs.
  • Oracle Banking Cash Management.
  • Oracle Banking Corporate Lending Process Management.
  • Oracle Banking Digital Experience.
  • MySQL Connectors.
  • MySQL Enterprise Backup.
  • Oracle Access Manager.

The complete list of the affected products: Oracle Advisory – October 2024

Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Oracle Advisory – October 2024

References