heartbleed patch for oracle RDBMS
I went thru the document provided it says that the Oracle Database [Product ID 5] does not include OpenSSL in their initial distribution (i.e., “out of the box”) and should therefore not be affected by the recent disclosure of CVE-2014-0160.
For OEM, here is the note from the document
Global Product Security has determined that the following products are using OpenSSL cryptographic libraries whose versions have been externally reported as not vulnerable to CVE-2014-0160 or did not use OpenSSL libraries to implement the vulnerable TLS protocol. No further action is therefore expected for these products:
- Enterprise manager grid control