Patch Reviews - DB (MOSC)

MOSC Banner

July Critical Patch update - client impact and what that means

edited Aug 11, 2016 5:00AM in Patch Reviews - DB (MOSC) 2 commentsAnswered ✓

In the July CPU, CVE-2016-3506 affects the client and is remotely executable without authentication. In this situation, how safe/unsafe are patched databases? Can an unpatched client where the vulnerability exists impact/leverage this vulnerability in a database even if the CPU patch is applied to the database, or are only unpatched databases vulnerable? Since I can't really control whether clients are patched or not, they can freely download vulnerable client versions somewhere on the Internet I'm sure for example, if a patched database is still vulnerable to an unpatched client then I'm wondering if I'm doing any good even patching so

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center