Vulnerability of unsupported version
Hi,
I have been asked about Oracle patch and what are the affected versions when Oracle releases CPU.
I’ll give an example, in the last CPU (October 2016) the CVE-2016-5555 was published for Oracle supported versions 11.2.0.4 and 12.1.0.2.
Oracle doesn’t mention if the previous versions 11.2.0.1, 11.2.0.2 and 12.1.0.1 are affected since patching was ended for these versions.
Does the previous versions are vulnerable?
In my case, I have an Oracle version 11.2.0.2 applied with the last patch which was released on October 2013.
Is my DB vulnerable?
Please advise.
Thanks in advance,
Ronen