OpenSSL Security Bug - Heartbleed CVE-2014-0160
Oracle’s security and development teams are aware of the recently disclosed vulnerability, which was reported to affect certain versions of OpenSSL (a.k.a. CVE-2014-0160; or ‘Heartbleed’).
Oracle is investigating the implications of this issue across the Oracle stack and the company has published a note on OTN about this issue. The URL for the OTN note is http://www.oracle.com/technetwork/topics/security/opensslheartbleedcve-2014-0160-2188454.html.
We will continue to investigate and this note will be updated with more information as we move forward.