CPU/PSU security bundles - patching strategy
We are working on a strategy to provide our applications with a realistic timeframe for patching the Oracle Database software with the CPU security vulnerability fixes.
I need an information/advise on that how proactively to apply the newly released CPU patches. I understand that Oracle strongly recommends applying the CPUs right after they are released, but it sounds a bit un-realistic to follow that recommendation when you have hundreds of database servers and many applications. I understand as well that Oracle provides an automatic patch updates, but in my case that's not possible since we are behind the firewall and no connection is allowed with the outside world.