This document defines the patches and minimum releases for the
Database Product Suite, Fusion Middleware Product Suite, and Enterprise
Manager Suite Critical Patch Updates and Patch Set Updates released on July
19, 2011.
PATCH SET UPDATE AND CRITICAL PATCH
UPDATE JULY 2011 AVAILABILITY DOCUMENT
Patch Set Update and Critical Patch
Update July 2011 Availability Document
My Oracle
Support Note 1323616.1
Released July 19th, 2011
This document contains the
following sections:
·
Section
1, "Overview"
·
Section
2, "What's New in July 2011"
·
Section
3, "Patch Availability for Oracle Products"
·
Section
4, "Final Patch History"
·
Section
5, "Sources of Additional Information"
·
Section
6, "Modification History"
·
Section
7, "Documentation Accessibility"
1 Overview
Every quarter, Oracle provides
Critical Patch Updates (CPU) to address security vulnerabilities, and Patch
Set Updates (PSU) to address proactive, critical fixes and security
vulnerabilities. The security vulnerabilities addressed are announced in
the Advisory for July 2011, available at http://www.oracle.com/technetwork/topics/security/cpujuly2011-313328.html.
This document lists the Oracle
Database, Fusion Middleware and Enterprise Manager CPU and PSU patches for
product releases under error correction. For information on products not
covered by this document, including Oracle Java SE Critical Patch Updates,
see http://www.oracle.com/technetwork/topics/security/alerts-086861.html.
The July 2011 release supersedes
earlier Critical Patch Updates and Patch Set Updates for the same product
releases. This document is subject to continual update after the initial
release, and the changes are listed in Section
6, "Modification History." If you
print this document, check My Oracle Support to ensure you have the latest
version.
This section contains the
following:
·
Section
1.1, "How To Use This Document"
·
Section
1.2, "Terminology in the Tables"
·
Section
1.3, "On-Request Patches"
·
Section
1.4, "Oracle Database Critical Patch Updates and Patch Set
Updates"
1.1 How To Use This Document
The following steps explain how to
use this document.
Step
1 Assess your Environments
Determine
the Oracle product suites and products and their release numbers for each
of your environments.
Step
2 Read Important Announcements
Review Section
2, "What's New in July 2011," as it lists documentation and packaging changes along
with important announcements such as upcoming final patches.
Step
3 Determine Patches to be Applied
For each
environment, determine which patches need to be applied by using the tables
in Section
3, "Patch Availability for Oracle Products."
The
product suite release tables may reference Section
3.1.3, "Oracle Database." You need
to determine the Oracle Database release that is installed, and find the
patches to apply in the table for that specific Oracle Database release.
All Oracle Database versions that are under error correction are listed in Section
3.1.3. If your installed Oracle Database
version does not have an associated table, then refer to Table
65, "Final Patch History" and
contact Oracle Support for further assistance.
There is
one availability table for each product suite release, such as Oracle
Database 11.1.0.7, Oracle Fusion Middleware 10.1.2.3, and Enterprise
Manager Grid Control 10.2.0.5. These tables list all the patches to apply
to the various Oracle homes that are associated with the product suite. The
patches are listed in the order to apply. Apply only the patches applicable
to the release that are installed in your environment. For example, the
Oracle Fusion Middleware 10.1.2.3 table lists an Oracle Portal Repository
patch for Oracle Portal 10.1.4.2 Repository, and a different patch for
Oracle Portal 10.1.2.3 Repository. Apply the corresponding patch based on
which release of Oracle Portal is installed in your system.
There is
one availability table for products that are released independently, such
as Oracle Secure Backup. Products may require a minimum release and/or list
of patches. This is dependent on the patching and release mechanisms for the
product. If a minimum release is indicated, the environment must be at that
release to address the announced security vulnerabilities.
The
tables list the CPU and PSU patches only for product versions that are
under error correction. For more information, see My Oracle Support Note
209768.1, Database, FMW, EM Grid Control, and OCS Software Error
Correction Support Policy.
Patches
that include security vulnerabilities announced in the current quarter's
CPU Advisory, will list the vulnerability CVE numbers in the Advisory
Number column. If you are interested in the risk matrix for the
vulnerabilities fixed in the patch, then see the CPU Advisory for the
release at http://www.oracle.com/technetwork/topics/security/alerts-086861.html. For patches that are listed from previous CPU
releases, the column will indicate 'Released MMM YYYY'. You can easily find
which patches are new in a CPU release by searching for the string 'CVE' in
the tables.
Step
4 Apply the Patches
Download
the patches, review the READMEs, and apply the patches according to the
instructions.
1.2 Terminology in the Tables
The following terminology is used
in this patch availability document and in the subsequent tables.
·
Bundle The Critical Patch Update and Patch Set Update fixes
are included in cumulative Microsoft Windows Bundles.
·
Patch Number The patch
is available on the platform for the release version.
·
Not Applicable (NA) The patch is not planned for this platform
and release version combination. This may be due to several reasons
including:
1.
The
release version is not available on this platform.
2.
The
release version does not fall under Critical Patch Update release policies.
Refer to My Oracle Support Note
209768.1, Database, FMW, EM Grid Control, and OCS Software Error
Correction Support Policy.
·
On-Request (OR) The patch may be made available through the
On-Request program.
1.3 On-Request Patches
Oracle does not release proactive
patches for platform-version combinations that have fewer than 10 downloads
in the prior Critical Patch Update (CPU) or Patch Set Update (PSU) period.
Oracle will deliver patches for these historically inactive
platform-version combinations when requested.
The following guidelines describe
how you may request an on-request (OR) Critical Patch Update or Patch Set
Update.
A request may be made:
·
At any
time. however a specific CPU/PSU cannot be requested. Either the current
CPU/PSU or the next CPU/PSU patch will be provided depending on when the
request is received and processed. Your Service Request (SR) will provide
you the planned availability date for the patch.
·
As long
as the version is in either Premier Support or Extended Support. Once the
final patch for the version has been released, an OR can be requested for
up to 2 weeks after the release date. For example, Oracle Database 10.1.0.5
is under Extended Support through the release of CPUJan2012 on January 17,
2012, so you can file a request for 10.1.0.5 through January 31, 2012.
·
For a
platform-version combination if the product or patch set is released on a
platform after a CPU/PSU release date. Oracle will provide the next CPU/PSU
for that platform-version combination, however you may request the current
CPU/PSU by following the on-request process. For example, if a 10.2.0.5
database patch set is released for a platform on August 1, 2011, Oracle
will provide the 10.2.0.5 CPUJul2011 for that platform. You may request a
10.2.0.5 CPUJul2011 on the platform, and Oracle will review the request and
determine whether to provide CPUJul2011 or CPUOct2011.
A patch that is marked as
on-request (OR) may already have been requested by another customer and be
available on My Oracle Support. Before you file a Service Request (SR),
check on My Oracle Support to see if the patch is already available for
your platform.
1.4 Oracle Database Critical
Patch Updates and Patch Set Updates
The Database Patch Set Updates and
Critical Patch Updates that are released each quarter contain the same
security fixes. However, they use different patching mechanisms, and Patch
Set Updates include both security and recommended bug fixes. Consider the
following guidelines when you are deciding to apply Patch Set Updates
instead of Critical Patch Updates.
·
Critical
Patch Updates are applied only on the base release version, for example
10.2.0.4.0.
·
Patch
Set Updates can be applied on the base release version or on any earlier
Patch Set Update. For example, 11.1.0.7.2 can be applied on 11.1.0.7.1 and
11.1.0.7.0.
·
Once a
Patch Set Update has been applied, the recommended way to get future
security content is to apply subsequent Patch Set Updates. Reverting from
an applied Patch Set Update back to the Critical Patch Update, while
technically possible, requires significant time and effort, and is not
advised.
For more information on Patch Set
Updates, see Note
854428.1, Patch Set Updates for Oracle Products.
2 What's New in July 2011
This section describes important
changes in July 2011:
·
Section
2.1, "Smart Update Tool Changes"
·
Section
2.2, "Additions to the On-Request Program"
·
Section
2.3, "Final Patch Information (Error Correction Policies)"
·
Section
2.4, "New Minimum Product Requirements for CPUJul2011"
·
Section
2.5, "New OPatch Requirements"
·
Section
2.6, "README Patch Apply Changes for Database and Fusion Middleware
Patches"
·
Section
2.7, "Changes to the Patch Availability Document"
·
Section
2.8, "Delayed CPU and PSU Patches"
2.1 Smart Update Tool Changes
WebLogic Net Installers and the
downloading of patches with Smart Update was decommissioned on June 10,
2011. For more information, see My Oracle Support Note Note
1294294.1. The patches that were previously
available through Smart Update have been migrated to My Oracle Support. You
can still access them by using the same bug number that was used with Smart
Update. Download the patches from My Oracle Support and use the Smart
Update client tool to apply the patches to your environment(s).
For more information, see the
following documents:
·
WebLogic Net Installers and Downloading of Patches Via
Smart Update To Be Decommissioned, Note
1294294.1
·
How to Locate and Download Patches for WebLogic Server
Using My Oracle Support, Note
1302053.1
·
What is New in Smart Update Version 3.3.0, http://download.oracle.com/docs/cd/E14759_01/doc.32/e14143/intro.htm#CEGEHDJH
2.2 Additions to the On-Request
Program
There are no new platforms that
have been added to the On-Request Program.
2.3 Final Patch Information
(Error Correction Policies)
Final patches for the July 2011 and
October 2011 releases, and newly scheduled final patches, are listed below.
July
2011 is the final patch for:
·
Oracle
Database 10.2.0.4 PSU and CPU for all platforms except Oracle Solaris x86
(32-bit) and Apple Mac OS X
·
Oracle
Database 11.2.0.1 PSU and CPU
October
2011 is the final patch for:
·
Oracle Identity
Management 10.1.4.3, except for Oracle Single Sign-on and Delegated
Administration Services working with Oracle Internet Directory 11gR1 for user authentication of Portal 11gR1, Forms 11gR1, Reports 11gR1 and Discoverer 11gR1
Middleware 11g PFRD
installation.
·
Oracle
Identity Management 10.1.4.0.1
·
Oracle
Fusion Middleware 10.1.2.3
For additional final patch history
information, see Table
65. For information on the error correction
support policy for patches, refer to My Oracle Support Note
209768.1, Database, FMW, EM Grid Control, and OCS Software Error
Correction Support Policy.
2.4 New Minimum Product
Requirements for CPUJul2011
There are no new minimum product
requirements for CPUJul2011.
2.5 New OPatch Requirements
There is one new minimum OPatch
requirement for July 2011:
·
OPatch
1.0.0.0.64. For more information, see Section
3.5.1, "Oracle Opatch."
2.6 README Patch Apply Changes
for Database and Fusion Middleware Patches
There are two README changes in
July 2011:
·
For
Oracle Database 11.2.0.2.3 Patch Set Update, an additional post-apply step
is required for customers using the Oracle Recovery Manager
·
For
Oracle Database 10.1.0.5, 10.2.0.4 and 10.2.0.5 environments, when
installing either the CPU or the PSU patch, you will need to run utlrp.sql as part of the post-installation
steps.
2.7 Changes to the Patch
Availability Document
The following changes to this
document are for July 2011:
·
An
Advisory Number column has been added to the patch availability tables. The
values in these fields enable you to map the patches in this document to
the security vulnerabilities announced in the Critical Patch Update
Advisory document. For more information, see Section 1.1, "How To Use
This Document."
·
Starting
with Oracle Fusion Middleware 11g and later versions, the Critical Patch
Updates for BEA products that have been integrated into Oracle Fusion
Middleware are listed in this document. Earlier BEA product releases
continue to be listed in My Oracle Support Note
1291845.1, Critical Patch Update April 2011
Patch Availability Document for Oracle BEA Releases.
·
The
information on Final Patch plans and on request platforms is presented in
tables for each product version.
2.8 Delayed CPU and PSU Patches
The following are the planned release
dates for the CPU and PSU patches that have been delayed. This section will
be updated as the patches are made available.
·
Oracle
Identity Management 11.1.1.4 and 11.1.1.5 Solaris x86 CPU
Available
August 1st, 2011
·
Oracle
Web Tier 11.1.1.4 and 11.1.1.5 Solaris x86 CPU
Available
August 1st, 2011
·
Oracle
Database PSU 10.2.0.5.4 BS2000 (SQ Series)
Available
July 20th, 2011
·
Oracle
Database 11.2.0.2 Microsoft Windows Bundle 9 including PSU content
Available
August 9th, 2011
·
Oracle
Database PSU 11.2.0.2.3 Linux on System Z
Available
August 5th, 2011
·
Oracle
Secure Enterprise Search 11.1.2.x Patch 12746118
Available
August 12th, 2011
3 Patch Availability for Oracle Products
This section contains the
following:
·
Section
3.1, "Oracle Database"
·
Section
3.2, "Oracle Fusion Middleware"
·
Section
3.3, "Oracle Enterprise Manager"
·
Section
3.4, "Oracle Collaboration"
·
Section
3.5, "Tools"
3.1 Oracle Database
This section contains the
following:
·
Section
3.1.1, "Oracle Application Express"
·
Section
3.1.2, "Oracle Audit Vault"
·
Section
3.1.3, "Oracle Database"
·
Section
3.1.4, "Oracle Database Patch Set Update (PSU)"
·
Section
3.1.5, "Oracle Fusion Middleware Utilities for Oracle Databases"
·
Section
3.1.6, "Oracle Secure Backup"
·
Section
3.1.7, "Oracle Secure Enterprise Search"
·
Section
3.1.8, "Oracle TimesTen"
·
Section
3.1.9, "Oracle Workflow Server"
3.1.1 Oracle Application
Express
Table
1 describes the minimum product requirements for Oracle
Application Express. The CPU security vulnerabilities are fixed in the
listed release and later releases. The Oracle Application Express downloads
and installation instructions can be found at http://www.oracle.com/technology/products/database/application_express/download.html.
Table 1 Minimum Product Requirements for
Oracle Application Express
Component
|
Release
|
Oracle Application Express
|
3.2.1.00.11
|
3.1.2 Oracle Audit Vault
Table
2 describes the available patches for Oracle Audit Vault
10.2.3.2, based on release and platform.
For each home you are about to
administer, find the appropriate patches based on the components installed
in that home. Then, apply those patches in the order listed.
Table 2 Patch Availability for Oracle Audit
Vault 10.2.3.2
Table
3 describes the available patches for Oracle Audit Vault
10.2.3.1, based on release and platform.
For each home you are about to
administer, find the appropriate patches based on the components installed
in that home. Then, apply those patches in the order listed.
Table 3 Patch Availability for Oracle Audit
Vault 10.2.3.1
3.1.3 Oracle Database
This section contains the
following:
·
Section
3.1.3.1, "Patch Availability for Oracle Database"
·
Section
3.1.3.2, "Oracle Database 11.2.0.2"
·
Section
3.1.3.3, "Oracle Database 11.2.0.1"
·
Section
3.1.3.4, "Oracle Database 11.1.0.7"
·
Section
3.1.3.5, "Oracle Database 10.2.0.5"
·
Section
3.1.3.6, "Oracle Database 10.2.0.4"
·
Section
3.1.3.7, "Oracle Database 10.2.0.3"
·
Section
3.1.3.8, "Oracle Database 10.1.0.5"
3.1.3.1 Patch Availability for Oracle Database
For Oracle Database 10.2.0.4 and
later releases, customers have the option to install the Critical Patch
Update (CPU) or the Patch Set Update (PSU). Both patch types are cumulative
patches. The PSU includes the security vulnerability bug fixes, as well as
additional non-security bug fixes recommended by Oracle. For more
information on PSU patches, see My Oracle Support Note
854428.1, Patch Set Updates (PSUs) for Oracle Products.
For the Microsoft Windows
platforms, Oracle Database patches are released as cumulative patch
bundles. You may install the indicated patch or any later bundle in the
Database Windows bundle series to apply the CPU security bug fixes. The
Windows patch bundles include the security vulnerability bug fixes, the PSU
recommended non-security bug fixes, and other customer-requested bug fixes.
3.1.3.2 Oracle Database 11.2.0.2
Table
4 describes the patch information for Oracle Database
11.2.0.2.
Table 4 Patch Information for Oracle
Database 11.2.0.2
Patch Information
|
11.2.0.2
|
Comments
|
Final patch
|
-
|
|
CPU On-Request platforms
|
HP-UX PA RISC
IBM: Linux on System Z
|
|
PSU On-Request platforms
|
32-bit client-only platforms except Linux x86
|
|
Table
5 describes the available patches for Oracle Database
11.2.0.2.
Table 5 Patch Availability for Oracle
Database 11.2.0.2
Oracle Database 11.2.0.2
|
UNIX
|
Microsoft Windows (32-Bit)
|
Microsoft Windows x64 (64-bit)
|
Advisory Number
|
Comments
|
Oracle Database home
|
CPU Patch 12419321, or DB PSU Patch 12419331, or GI PSU Patch 12419353, or Exadata BP9 Patch 12681774
|
Bundle Patch 12714462
|
Bundle Patch 12714463
|
CVE-2011-0816, CVE-2011-0831, CVE-2011-0832,
CVE-2011-0835, CVE-2011-0838, CVE-2011-0848, CVE-2011-0870,
CVE-2011-0876, CVE-2011-0879, CVE-2011-0880, CVE-2011-2239,
CVE-2011-2242, CVE-2011-2243, CVE-2011-2244, CVE-2011-2248,
CVE-2011-2253, CVE-2011-2257
|
|
3.1.3.3 Oracle Database 11.2.0.1
Table
6 describes the patch information for Oracle Database
11.2.0.1
Table 6 Patch Information for Oracle
Database 11.2.0.1
Patch Information
|
11.2.0.1
|
Comments
|
Final patch
|
July 2011
|
|
CPU On-Request platforms
|
32-bit client-only platforms except Linux x86
|
|
PSU On-Request platforms
|
32-bit client-only platforms except Linux x86
|
|
Table
7 describes the available patches for Oracle Database
11.2.0.1.
Table 7 Patch Availability for Oracle
Database 11.2.0.1
Oracle Database 11.2.0.1
|
UNIX
|
Microsoft Windows (32-Bit)
|
Microsoft Windows x64 (64-bit)
|
Advisory Number
|
Comments
|
Oracle Database home
|
CPU Patch 12419278, or DB PSU Patch 12419378, or Exadata BP11 Patch 12608545
|
Bundle Patch 12429528
|
Bundle Patch 12429529
|
CVE-2011-0816, CVE-2011-0831, CVE-2011-0832,
CVE-2011-0835, CVE-2011-0838, CVE-2011-0848, CVE-2011-0870,
CVE-2011-0876, CVE-2011-0879, CVE-2011-0880, CVE-2011-2230,
CVE-2011-2231, CVE-2011-2232, CVE-2011-2238, CVE-2011-2239,
CVE-2011-2242, CVE-2011-2243, CVE-2011-2244, CVE-2011-2248,
CVE-2011-2253, CVE-2011-2257
|
|
Oracle Database home (Database UIX)
|
Patch 9288120
|
Patch 9288120
|
Patch 9288120
|
Released April 2011
|
|
Oracle Database home (Enterprise Manager Database
Control UIX)
|
Patch 10073948
|
Patch 10073948
|
Patch 10073948
|
Released April 2011
|
|
Oracle Database home (Warehouse Builder)
|
Patch 11738254
|
Patch 11738254
|
Patch 11738254
|
Released April 2011
|
|
3.1.3.4 Oracle Database 11.1.0.7
Table
8 describes the patch information for Oracle Database
11.1.0.7.
Table 8 Patch Information for Oracle
Database 11.1.0.7
Patch Information
|
11.1.0.7
|
Comments
|
Final patch
|
July 2015
|
|
CPU On-Request platforms
|
-
|
|
PSU On-Request platforms
|
-
|
|
Table
9 describes the available patches for Oracle Database
11.1.0.7.
Table 9 Patch Availability for Oracle
Database 11.1.0.7
Oracle Database 11.1.0.7
|
UNIX
|
Microsoft Windows (32-Bit)
|
Microsoft Windows x64 (64-Bit)
|
Advisory Number
|
Comments
|
Oracle Database home
|
CPU Patch 12419265, or PSU Patch 12419384
|
Bundle Patch 12695277
|
Bundle Patch 12695278
|
CVE-2011-0816, CVE-2011-0831, CVE-2011-0832,
CVE-2011-0835, CVE-2011-0838, CVE-2011-0848, CVE-2011-0870, CVE-2011-0875,
CVE-2011-0876, CVE-2011-0879, CVE-2011-0880, CVE-2011-0881,
CVE-2011-0882, CVE-2011-2230, CVE-2011-2231, CVE-2011-2232,
CVE-2011-2238, CVE-2011-2239, CVE-2011-2243, CVE-2011-2244,
CVE-2011-2248, CVE-2011-2253, CVE-2011-2257
|
|
Oracle Database home (Database UIX)
|
Patch 9288120
|
Patch 9288120
|
Patch 9288120
|
Released April 2011
|
For Oracle Secure Enterprise Search 11.1.2.x
installations, Database UIX Patch 9288120 must
be applied only after applying Patch 12746118. The availability of Patch 12746118 is
currently pending.
|
Oracle Database home (Enterprise Manager Database
Control UIX)
|
Patch 10073948
|
Patch 10073948
|
Patch 10073948
|
Released April 2011
|
Not applicable to Oracle Secure Enterprise Search
11.1.2.x
|
Oracle Database home (Warehouse Builder)
|
Patch 11738232
|
Patch 11738232
|
Patch 11738232
|
Released April 2011
|
Not applicable to Oracle Secure Enterprise Search
11.1.2.x
|
3.1.3.5 Oracle Database 10.2.0.5
Table
10 describes the patch information for Oracle Database
10.2.0.5.
Table 10 Patch Information for Oracle
Database 10.2.0.5
Patch Information
|
10.2.0.5
|
Comments
|
Final patch
|
July 2013
|
|
CPU On-Request platforms
|
HP-UX PA-RISC
IBM: Linux on System Z
Linux Itanium
Linux on POWER
|
|
PSU On-Request platforms
|
-
|
|
Table
11 describes the available patches for Oracle Database
10.2.0.5.
Table 11 Patch Availability for Oracle
Database 10.2.0.5
Oracle Database 10.2.0.5
|
UNIX
|
Microsoft Windows (32-Bit)
|
Microsoft Windows Itanium
(64-Bit)
|
Microsoft Windows x64 (64-Bit)
|
Advisory Number
|
Comments
|
Oracle Database home
|
CPU Patch 12419258, or PSU Patch 12419392
|
Bundle Patch 12429523
|
NA
|
Bundle Patch 12429524
|
CVE-2011-0816, CVE-2011-0831, CVE-2011-0848,
CVE-2011-0870, CVE-2011-0876, CVE-2011-0879, CVE-2011-2230,
CVE-2011-2231, CVE-2011-2238, CVE-2011-2239, CVE-2011-2244,
CVE-2011-2253, CVE-2011-2257
|
|
Oracle Database home (Enterprise Manager Database
Control)
|
Patch 12536181
|
NA
|
NA
|
NA
|
CVE-2011-0811
|
For HP-UX PA-RISC and HP-UX Itanium platforms only
|
Oracle Database home (Warehouse Builder)
|
Patch 11738172
|
Patch 11738172
|
Patch 11738172
|
Patch 11738172
|
Released April 2011
|
|
3.1.3.6 Oracle Database 10.2.0.4
Table
12 describes the patch information for Oracle Database
10.2.0.4.
Table 12 Patch Information for Oracle
Database 10.2.0.4
Patch Information
|
10.2.0.4
|
Comments
|
Final patch
|
July 2011
|
July 2013 for Oracle Solaris x86 (32-bit) and Apple Mac
OS X only
|
CPU On-Request platforms
|
Apple Mac OS X
HP Open VMS-Alpha
HP Open VMS-Itanium
HP Tru64 UNIX
IBM: Linux on System Z
Linux Itanium
Linux on POWER
Oracle Solaris x86 (32-bit)
|
|
PSU On-Request platforms
|
-
|
-
|
Table
13 describes the available patches for Oracle Database
10.2.0.4.
Table 13 Patch Availability for Oracle
Database 10.2.0.4
Oracle Database 10.2.0.4
|
UNIX
|
Microsoft Windows (32-Bit)
|
Microsoft Windows Itanium
(64-Bit)
|
Microsoft Windows x64 (64-Bit)
|
Advisory Number
|
Comments
|
Oracle Database home
|
CPU Patch 12419249, or PSU Patch 12419397
|
Bundle Patch 12429519
|
Bundle Patch 12429520
|
Bundle Patch 12429521
|
CVE-2011-0816, CVE-2011-0830, CVE-2011-0831,
CVE-2011-0848, CVE-2011-0852, CVE-2011-0870, CVE-2011-0876,
CVE-2011-0877, CVE-2011-0879, CVE-2011-0881, CVE-2011-0882,
CVE-2011-2230, CVE-2011-2231, CVE-2011-2232, CVE-2011-2238,
CVE-2011-2239, CVE-2011-2244, CVE-2011-2253, CVE-2011-2257
|
|
Oracle Database home (Enterprise Manager Database
Control)
|
Patch 12536167
|
NA
|
NA
|
NA
|
CVE-2011-0811
|
For HP-UX PA-RISC and HP-UX Itanium platforms only
|
Oracle Database home (Database UIX)
|
Patch 9249369
|
Patch 9249369
|
Patch 9249369
|
Patch 9249369
|
Released April 2011
|
|
Oracle Database home (Enterprise Manager Database
Control UIX)
|
Patch 12758181
|
Patch 12758181
|
Patch 12758181
|
Patch 12758181
|
Replacement for CPUApr2011 Patch 10077139
|
|
Oracle Database home (iSqlPlus UIX)
|
Patch 9273865
|
Patch 9273865
|
Patch 9273865
|
Patch 9273865
|
Released April 2011
|
|
3.1.3.7 Oracle Database 10.2.0.3
Table
14 describes the patch information for Oracle Database
10.2.0.3.
Table 14 Patch Information for Oracle
Database 10.2.0.3
Patch Information
|
10.2.0.3
|
Comments
|
Final patch
|
-
|
IBM zSeries (z/OS) only
|
CPU On-Request platforms
|
-
|
|
Table
15 describes the available patches for Oracle Database
10.2.0.3.
Table 15 Patch Availability for Oracle
Database 10.2.0.3
Component
|
IBM zSeries (z/OS)
|
Advisory Number
|
Comments
|
Oracle Database home
|
CPU Patch 12419246
|
CVE-2011-0816, CVE-2011-0822, CVE-2011-0830,
CVE-2011-0831, CVE-2011-0848, CVE-2011-0852, CVE-2011-0870,
CVE-2011-0876, CVE-2011-0877, CVE-2011-0879, CVE-2011-0881,
CVE-2011-0882, CVE-2011-2230, CVE-2011-2231, CVE-2011-2232,
CVE-2011-2238, CVE-2011-2239, CVE-2011-2244, CVE-2011-2253, CVE-2011-2257
|
|
3.1.3.8 Oracle Database 10.1.0.5
For Fusion Middleware 10.1.2.3
customers, see Table
43, "Patch Availability for Oracle Fusion Middleware 10.1.2.3" instead of Table
17.
Table
16 describes the patch information for Oracle Database
10.1.0.5.
Table 16 Patch Information for Oracle
Database 10.1.0.5
Patch Information
|
10.1.0.5
|
Comments
|
Final patch
|
January 2012
|
|
CPU On-Request platforms
|
Apple Mac OS X
HP Open VMS Alpha
HP Tru64 UNIX
IBM zSeries (z/OS)
Linux Itanium
Linux on POWER
Oracle Solaris x86 (32-bit)
|
|
Table
17 describes the available patches for Oracle Database
10.1.0.5.
Table 17 Patch Availability for Oracle
Database 10.1.0.5
Oracle Database 10.1.0.5
|
UNIX
|
Microsoft Windows (32-Bit)
|
Microsoft Windows Itanium
(64-Bit)
|
Advisory Number
|
Comments
|
Oracle Database home (Oracle Universal Installer)
|
Patch 6640838
|
Patch 6640838
|
Patch 6640838
|
Released October 2010
|
|
Oracle Database home (Oracle Universal Installer)
|
Patch 11842285
|
NA
|
NA
|
CVE-2011-2240
|
|
Oracle Database home
|
CPU Patch 12419228
|
Bundle Patch 12429517
|
Bundle Patch 12429518
|
CVE-2011-0816, CVE-2011-0822, CVE-2011-0830,
CVE-2011-0831, CVE-2011-0848, CVE-2011-0852, CVE-2011-0870,
CVE-2011-0876, CVE-2011-0877, CVE-2011-0879, CVE-2011-0882,
CVE-2011-2230, CVE-2011-2231, CVE-2011-2232, CVE-2011-2244, CVE-2011-2257
|
|
Oracle Database home (Enterprise Manager Database
Control)
|
Patch 12535977
|
NA
|
NA
|
CVE-2011-0811
|
For HP-UX PA-RISC and HP-UX Itanium platforms only
|
Oracle Workspace Manager home
|
Patch 7341989
|
Patch 7341989
|
Patch 7341989
|
Released April 2009
|
|
Oracle Database home (Database UIX)
|
Patch 9249369
|
Patch 9249369
|
Patch 9249369
|
Released April 2011
|
|
Oracle Database home (Enterprise Manager Database
Control UIX)
|
Patch 10036362
|
Patch 10036362
|
Patch 10036362
|
Released April 2011
|
|
Oracle Database home (iSqlPlus UIX)
|
Patch 9273888
|
Patch 9273888
|
Patch 9273888
|
Released April 2011
|
|
3.1.4 Oracle Database
Patch Set Update (PSU)
Table
18 lists the patches for Oracle Database patch set
updates. For complete security patch information, see Section
3.1.3, "Oracle Database."
As Windows Bundles are cumulative,
you may apply the patch indicated in Table
7 or any later bundle in the Windows bundle series to
obtain the Patch Set Update bug fixes.
Table 18 Patch Set Update Availability for
Oracle Database
3.1.5 Oracle Fusion
Middleware Utilities for Oracle Databases
Table
19 lists the patches for
Oracle Fusion Middleware components, such as Oracle HTTP Server, which are
installed using the Oracle Database Companion CD. For information about
Oracle Fusion Middleware 11g, see My Oracle
Support Note
1304604.1, Oracle Fusion Middleware 11g Web-Tier FAQ, and Section
3.2.8, "Oracle Fusion Middleware."
Table 19 Patch Availability for Oracle
Fusion Middleware Utilities for Oracle Databases
Product
|
UNIX
|
Microsoft Windows (32-Bit)
|
Microsoft Windows Itanium
(64-Bit)
|
Advisory Number
|
Comments
|
Oracle HTTP Server 10.1.2.3 for Oracle 10.2.x
Databases
|
CPU Patch 12434134
|
Bundle Patch 12434141
|
Bundle Patch 12434144
|
CVE-2011-0816, CVE-2011-0822, CVE-2011-0830,
CVE-2011-0831, CVE-2011-0848, CVE-2011-0852, CVE-2011-0870,
CVE-2011-0876, CVE-2011-0877, CVE-2011-0879, CVE-2011-0882,
CVE-2011-2230, CVE-2011-2231, CVE-2011-2232, CVE-2011-2244,
CVE-2011-2257, CVE-2011-0883
|
See My Oracle Support Note
400010.1 Steps to Maintain Oracle Database 10.2 Companion CD Home
(for Oracle HTTP Server)
|
3.1.6 Oracle Secure Backup
Table
20 describes the available patches for Oracle Secure
Backup.
Table 20 Patch Availability for Oracle
Secure Backup
Oracle Secure Backup
|
Patch
|
Advisory Number
|
Comments
|
Release 10.3.0.3
|
Patch 12573094
|
CVE-2011-2251, CVE-2011-2252, CVE-2011-2261
|
|
3.1.7 Oracle Secure
Enterprise Search
Table
21 describes the available patches for Oracle Secure
Enterprise Search 11.1.2.x.
Table 21 Patch Availability for Oracle
Secure Enterprise Search 11.1.2.x
Table
22 describes the available patches for Oracle Secure
Enterprise Search 10.1.8.x.
Table 22 Patch Availability for Oracle
Secure Enterprise Search 10.1.8.x
3.1.8 Oracle TimesTen
Table
23 describes the minimum product requirements for Oracle
TimesTen. The CPU security vulnerabilities are fixed in the listed release
and later releases.
Table 23 Minimum Product Requirements for
Oracle TimesTen
Oracle TimesTen Release
|
11.2.1.6.1
|
7.0.6.2.0
|
3.1.9 Oracle Workflow
Server
Table
24 describes the available patches for Oracle Workflow
Server.
Table 24 Patch Availability for Oracle
Workflow Server
3.2 Oracle Fusion Middleware
This section contains the
following:
·
Section
3.2.1, "Oracle BEA Releases"
·
Section
3.2.2, "Oracle Beehive"
·
Section
3.2.3, "Oracle Business Intelligence Enterprise Edition"
·
Section
3.2.4, "Oracle Business Intelligence Publisher"
·
Section
3.2.5, "Oracle COREid"
·
Section
3.2.6, "Oracle Document Capture"
·
Section
3.2.7, "Oracle Exalogic Patch Set Update (PSU)"
·
Section
3.2.8, "Oracle Fusion Middleware"
·
Section
3.2.9, "Oracle GoldenGate Veridata"
·
Section
3.2.10, "Oracle Hyperion BI+"
·
Section
3.2.11, "Oracle Identity Manager"
·
Section
3.2.12, "Oracle JRockit"
·
Section
3.2.13, "Oracle Outside In Technology"
·
Section
3.2.14, "Oracle WebLogic Server"
·
Section
3.2.15, "Oracle WebLogic Server Patch Set Update (PSU)"
·
Section
3.2.16, "Oracle WebLogic Server Plug-ins"
3.2.1 Oracle BEA Releases
Table
25 describes the available patches for Oracle BEA Releases
based on release and platform. The patches for the BEA components are
documented in My Oracle Support Note
1323601.1, Critical Patch Update July 2011 Patch Availability Document
for Oracle BEA Releases.
For each home you are about to
administer, find the appropriate patches based on the components installed
in that home. Then, apply those patches in the order listed.
Table 25 Patch Availability for Oracle BEA
Releases
Component
|
Patch
|
Advisory Number
|
Comments
|
Oracle Database home
|
See Section
3.1.3, "Oracle Database"
|
See Section
3.1.3, "Oracle Database"
|
|
Oracle Business Process Management
Oracle Complex Event Processing and WebLogic Event
Server
Oracle Data Service Integrator and AquaLogic Data
Services Platform
Oracle JRockit
Oracle WebLogic Integration
Oracle WebLogic Portal
Oracle WebLogic Server and WebLogic Express
Oracle WebLogic Server Plug-ins
|
|
|
See My Oracle Support Note
1323601.1
|
3.2.2 Oracle Beehive
This section contains the
following:
·
Section
3.2.2.1, "Minimum Product Requirements for Oracle Beehive"
·
Section
3.2.2.2, "Patch Availability for Oracle Beehive 2.0.1.x"
·
Section
3.2.2.3, "Patch Availability for Oracle Beehive 1.5.1.x"
3.2.2.1 Minimum Product Requirements for Oracle Beehive
Table
26 describes the minimum product requirements for Oracle
Beehive.
Table 26 Minimum Product Requirements for
Oracle Beehive
Oracle Beehive
|
Release
|
Advisory Number
|
Oracle Beehive 2.0.1.x
|
2.0.1.4
|
Announced January 2011
|
3.2.2.2 Patch Availability for Oracle Beehive 2.0.1.x
Oracle Beehive environments contain
Oracle Database and Oracle Fusion Middleware homes. For more information,
see My Oracle Support Note
758816.1, Applying Critical Patch Updates to Beehive 1.5.1.x though
2.0.1.x.
Table
27 describes the available patches for Oracle Beehive
2.0.1.x.
For each home you are about to
administer, find the appropriate patches based on the components installed
in that home. Then, apply those patches in the order listed.
Table 27 Patch Availability for Oracle
Beehive 2.0.1.x
3.2.2.3 Patch Availability for Oracle Beehive 1.5.1.x
Table
28 describes the available patches for Oracle Beehive
1.5.1.x. For information on Oracle Database and Oracle Fusion Middleware
Critical Patch Updates that apply to Beehive homes, see My Oracle Support Note
758816.1, Applying Critical Patch Updates to Beehive 1.5.1.x though
2.0.1.x.
For each home you are about to
administer, find the appropriate patches based on the components installed
in that home. Then, apply those patches in the order listed.
Table 28 Patch Availability for Oracle Beehive
1.5.1.x
3.2.3 Oracle Business Intelligence
Enterprise Edition
Table
29 describes the available patches for Oracle Business Intelligence
Enterprise Edition.
Customers on earlier versions of
Oracle Business Intelligence Enterprise Edition 10.x will need to apply
10.1.3.4.1 and then apply the Critical Patch Update.
Table 29 Patch Availability for Oracle
Business Intelligence Enterprise Edition
Oracle Business Intelligence
Enterprise Edition
|
Patch
|
Advisory Number
|
Comments
|
11.1.1.3.0
|
Patch 11833750
|
CVE-2011-2241
|
OBIEE Patch
|
10.1.3.4.1
|
Patch 11833743
|
CVE-2011-2241
|
OBIEE Patch
|
11.1.1.3.0
|
Patch 10411254
|
Released January 2011
|
BIP Patch
|
10.1.3.4.1
|
Patch 10623023
|
Released January 2011
|
BIP Patch
|
3.2.4 Oracle Business
Intelligence Publisher
Table
30 describes the available patches for Oracle Business
Intelligence Publisher.
Customers on earlier versions of
Oracle Business Intelligence Publisher 10.x will need to apply 10.1.3.4.1
and then apply the Critical Patch Update.
Table 30 Patch Availability for Oracle
Business Intelligence Publisher
Oracle Business Intelligence
Publisher
|
Patch
|
Advisory Number
|
Comments
|
11.1.1.3.0
|
Patch 10411254
|
Released January 2011
|
|
10.1.3.4.1
|
Patch 10623023
|
Released January 2011
|
See My Oracle Support Note
797057.1, Overview of Available Update Patches for Oracle BI Publisher
Enterprise 10g
|
3.2.5 Oracle COREid
Table
31 describes the available patches for Oracle COREid.
Customers on earlier versions of Oracle COREid will need to apply the
patches listed below.
Table 31 Patch Availability for Oracle
COREid
Oracle COREid
|
Patch
|
Advisory Number
|
Comments
|
10.1.4.2
|
Patch 8350593
|
Released January 2010
|
|
7.0.4.3
|
Patch 8593692
|
Released January 2010
|
|
3.2.6 Oracle Document
Capture
Table
32 describes the available patches for Oracle Document
Capture.
Table 32 Patch Availability for Oracle
Document Capture
Oracle Document Capture
|
Patch
|
Advisory Number
|
Comments
|
Oracle Document Capture 10.1.3.5 home
|
Patch 10350692
|
Released January 2011
|
|
Oracle Document Capture 10.1.3.4 home
|
Patch 10350692
|
Released January 2011
|
|
3.2.7 Oracle Exalogic Patch
Set Update (PSU)
Table
33 describes the available patch set update (PSU) for
Oracle Exalogic.
Table 33 Patch Set Update Availability for
Oracle Exalogic
Oracle Exalogic
|
Patch
|
Advisory Number
|
Comments
|
July 2011
|
Patch 12634555
|
CVE-2011-0873
|
See Note
1314535.1, Announcing Exalogic PSUs (Patch Set Updates)
Oracle Exalogic PSU is available only for Linux
x86-64 and Oracle Solaris x86-64 platforms
|
3.2.8 Oracle Fusion
Middleware
Additional information may be found
in My Oracle Support Note
405972.1, Oracle Application Server 10g Examples for Critical Patch
Updates - Plus FMW 11g.
This section contains the
following:
·
Section
3.2.8.1, "Patch Availability for Oracle Fusion Middleware
11.1.1.5"
·
Section
3.2.8.2, "Patch Availability for Oracle Fusion Middleware
11.1.1.4"
·
Section
3.2.8.3, "Patch Availability for Oracle Fusion Middleware
11.1.1.3"
·
Section
3.2.8.4, "Patch Availability for Oracle Fusion Middleware
10.1.3.5.x"
·
Section
3.2.8.5, "Patch Availability for Oracle Fusion Middleware
10.1.2.3"
·
Section
3.2.8.6, "Patch Availability for Oracle Identity Management
10.1.4.3"
·
Section
3.2.8.7, "Patch Availability for Oracle Identity Management
10.1.4.0.1"
3.2.8.1 Patch Availability for Oracle Fusion Middleware 11.1.1.5
Table
34 describes the patch information for Oracle Fusion
Middleware 11.1.1.5.
Table 34 Patch Information for Oracle Fusion
Middleware 11.1.1.5
Patch Information
|
11.1.1.5
|
Comments
|
Final Patch
|
-
|
|
CPU On Request Platforms
|
-
|
|
Table
35 describes the available patches for Oracle Fusion
Middleware 11.1.1.5.
For each home you are about to
administer, find the appropriate patches based on the components installed
in that home. Then, apply those patches in the order listed.
Table 35 Patch Availability for Oracle
Fusion Middleware 11.1.1.5
Oracle Fusion Middleware
11.1.1.5.0
|
Patches
|
Advisory Number
|
Comments
|
Oracle Database home
|
See Section
3.1.3, "Oracle Database"
|
See Section
3.1.3, "Oracle Database"
|
|
Oracle JRockit 28.1.x home
|
CPU Patch 12706519
|
CVE-2011-0873
|
|
Oracle WebLogic Server Plug-ins 1.0
|
CPU Patch 11845433
|
Released April 2011
|
See Note
1111903.1, WebLogic Server 10gR3 (10.3.0) and 11gR1 (10.3.x) - Web
Server Plug-In Support
|
Oracle Identity Management 11.1.1.5.0 home
Oracle Web Tier 11.1.1.5.0 home
|
CPU Patch 12434187
|
CVE-2010-1321
|
Network
For Solaris x86-64, (Identity Management and Web Tier
homes), apply specific mandatory patches. For more information, see My
Oracle Support Note
1343107.1
|
Oracle Single Sign-On / Delegated Administration
Services home
|
Unix: Patch 12434134
Microsoft Windows 32-bit: Patch 12434141
Microsoft Windows Itanium 64-bit: Patch 12434144
|
CVE-2011-0816, CVE-2011-0822, CVE-2011-0830,
CVE-2011-0831, CVE-2011-0848, CVE-2011-0852, CVE-2011-0870,
CVE-2011-0876, CVE-2011-0877, CVE-2011-0879, CVE-2011-0882,
CVE-2011-2230, CVE-2011-2231, CVE-2011-2232, CVE-2011-2244,
CVE-2011-2257, CVE-2011-0883
|
See Note
1301699.1, How the SSL/TLS Renegotiation Protocol Change Affects Oracle
HTTP Server
|
3.2.8.2 Patch Availability for Oracle Fusion Middleware 11.1.1.4
Table
36 describes the patch information for Oracle Fusion
Middleware 11.1.1.4.
Table 36 Patch Information for Oracle Fusion
Middleware 11.1.1.4
Patch Information
|
11.1.1.4
|
Comments
|
Final Patch
|
April 2012
|
|
CPU On Request Platforms
|
-
|
|
Table
37 describes the available patches for Oracle Fusion
Middleware 11.1.1.4.
For each home you are about to
administer, find the appropriate patches based on the components installed
in that home. Then, apply those patches in the order listed. For
information about the different types of installations, see My Oracle
Support Note
405972.1.
Table 37 Patch Availability for Oracle
Fusion Middleware 11.1.1.4
Oracle Fusion Middleware 11.1.1.4
|
Patches
|
Advisory Number
|
Comments
|
Oracle Database home
|
See Section
3.1.3, "Oracle Database"
|
See Section
3.1.3, "Oracle Database"
|
|
Oracle JRockit 28.1.x home
|
CPU Patch 12706519
|
CVE-2011-0873
|
|
Oracle WebLogic Server 10.3.4.0.2
|
Patch 12357891
|
NA
|
See Note
1306505.1, Announcing Oracle WebLogic Server PSUs (Patch Set Updates)
|
Oracle WebLogic Server Plug-ins 1.0
|
CPU Patch 11845433
|
Released April 2011
|
See Note
1111903.1, WebLogic Server 10gR3 (10.3.0) and 11gR1 (10.3.x) - Web
Server Plug-In Support
|
Oracle Identity Management 11.1.1.4.0 home
Oracle Portal, Forms, Reports and Discoverer
11.1.1.4.0 home
Oracle Web Tier 11.1.1.4.0 home
|
CPU Patch 12434184
|
CVE-2010-1321
|
Network
For Solaris x86-64, (Identity Management and Web Tier
homes), apply specific mandatory patches. For more information, see My
Oracle Support Note
1343107.1
|
Oracle Single Sign-On / Delegated Administration
Services home
|
Unix: Patch 12434134
Microsoft Windows 32-bit: Patch 12434141
Microsoft Windows Itanium 64-bit: Patch 12434144
|
CVE-2011-0816, CVE-2011-0822, CVE-2011-0830,
CVE-2011-0831, CVE-2011-0848, CVE-2011-0852, CVE-2011-0870,
CVE-2011-0876, CVE-2011-0877, CVE-2011-0879, CVE-2011-0882,
CVE-2011-2230, CVE-2011-2231, CVE-2011-2232, CVE-2011-2244,
CVE-2011-2257, CVE-2011-0883
|
See Note
1301699.1, How the SSL/TLS Renegotiation Protocol Change Affects Oracle
HTTP Server
|
3.2.8.3 Patch Availability for Oracle Fusion Middleware 11.1.1.3
Table
38 describes the patch information for Oracle Fusion
Middleware 11.1.1.3.
Table 38 Patch Information for Oracle Fusion
Middleware 11.1.1.3
Patch Information
|
11.1.1.3
|
Comments
|
Final Patch
|
January 2012
|
|
CPU On Request Platforms
|
-
|
|
Table
39 describes the available patches for Oracle Fusion
Middleware 11.1.1.3.
For each home you are about to
administer, find the appropriate patches based on the components installed
in that home. Then, apply those patches in the order listed.
Table 39 Patch Availability for Oracle
Fusion Middleware 11.1.1.3
Oracle Fusion Middleware 11.1.1.3
|
Patches
|
Advisory Number
|
Comments
|
Oracle Database home
|
See Section
3.1.3, "Oracle Database"
|
See Section
3.1.3, "Oracle Database"
|
|
Oracle JRockit 28.1.x home
|
Patch 12706519
|
CVE-2011-0873
|
|
Oracle WebLogic Server Plug-ins 1.0
|
Patch 11845433
|
Released April 2011
|
See Note
1111903.1, WebLogic Server 10gR3 (10.3.0) and 11gR1 (10.3.x) - Web
Server Plug-In Support
|
Oracle WebLogic Server 10.3.3.0 home
|
Patch 10625613
Patch 10625676
|
Released January 2011
Released January 2011
|
|
Oracle Identity Management 11.1.1.3.0 home
Oracle Portal, Forms, Reports and Discoverer
11.1.1.3.0 home
Oracle Web Tier 11.1.1.3.0 home
|
Patch 10387726
|
Released January 2011
|
Oracle HTTP Server
|
Oracle Identity Management 11.1.1.3.0 home
Oracle Portal, Forms, Reports and Discoverer
11.1.1.3.0 home
Oracle Web Tier 11.1.1.3.0 home
|
Patch 12434180
|
CVE-2010-1321
|
Network
See Note
1301699.1, How the SSL/TLS Renegotiation Protocol Change Affects Oracle
HTTP Server
|
Oracle Portal, Forms, Reports and Discoverer
11.1.1.3.0 home
|
Patch 10233533
|
Released January 2011
|
Discoverer
|
Oracle Single Sign-On / Delegated Administration
Services home
|
Unix: Patch 12434134
Microsoft Windows 32-bit: Patch 12434141
Microsoft Windows Itanium 64-bit: Patch 12434144
|
CVE-2011-0816, CVE-2011-0822, CVE-2011-0830,
CVE-2011-0831, CVE-2011-0848, CVE-2011-0852, CVE-2011-0870,
CVE-2011-0876, CVE-2011-0877, CVE-2011-0879, CVE-2011-0882,
CVE-2011-2230, CVE-2011-2231, CVE-2011-2232, CVE-2011-2244,
CVE-2011-2257, CVE-2011-0883
|
See Note
1301699.1, How the SSL/TLS Renegotiation Protocol Change Affects Oracle
HTTP Server
|
3.2.8.4 Patch Availability for Oracle Fusion Middleware 10.1.3.5.x
Table
40 describes the patch information for Oracle Fusion
Middleware 10.1.3.5.x.
Table 40 Patch Information for Oracle Fusion
Middleware 10.1.3.5.x
Patch Information
|
10.1.3.5.x
|
Comments
|
Final Patch
|
Oracle SOA Suite: October 2014
Other 10.1.3.5.x components: July 2017
|
For more information, see Lifetime
Support Policy for Oracle Fusion Middleware
|
CPU On Request Platforms
|
-
|
|
Table
41 describes the available patches for Oracle Fusion
Middleware 10.1.3.5.x.
For each home you are about to
administer, find the appropriate patches based on the components installed
in that home. Then, apply those patches in the order listed. For
information about the different types of installations, see My Oracle
Support Note
405972.1, Oracle Application Server 10g Examples for Critical Patch
Updates - Plus FMW 11g.
Table 41 Patch Availability for Oracle
Fusion Middleware 10.1.3.5.x
3.2.8.5 Patch Availability for Oracle Fusion Middleware 10.1.2.3
Table
42 describes the patch information for Oracle Fusion
Middleware 10.1.2.3
Table 42 Patch Information for Oracle Fusion
Middleware 10.1.2.3
Patch Information
|
10.1.2.3
|
Comments
|
Final Patch
|
October 2011
|
|
CPU On Request Platforms
|
HP-Tru64 Unix
Linux Itanium
Linux on Power
|
|
Table
43 describes the available patches for Oracle Fusion
Middleware 10.1.2.3.
For each home you are about to
administer, find the appropriate patches based on the components installed
in that home. Then, apply those patches in the order listed. For
information about the different types of installations, see My Oracle
Support Note
405972.1, Oracle Application Server 10g Examples for Critical Patch
Updates.
Table 43 Patch Availability for Oracle
Fusion Middleware 10.1.2.3
Oracle Fusion Middleware 10.1.2.3
|
Patch
|
Advisory Number
|
Comments
|
Oracle Database home
|
See Section
3.1.3, "Oracle Database"
|
See Section
3.1.3, "Oracle Database"
|
Separate Database homes only
|
Infrastructure home
Middle Tier home
Developer Suite home
|
Patch 6640838
|
Released January 2010
|
Oracle Universal Installer patch
See Note
565374.1 for
information on installing this patch
|
Infrastructure home
Middle Tier home
Developer Suite home
|
Patch 11842285
|
CVE-2011-2240
|
Oracle Universal Installer patch
|
Infrastructure home
Middle tier home
Developer Suite home
|
Unix: Patch 12434134
Microsoft Windows 32-bit: Patch 12434141
Microsoft Windows Itanium 64-bit: Patch 12434144
|
CVE-2011-0816, CVE-2011-0822, CVE-2011-0830,
CVE-2011-0831, CVE-2011-0848, CVE-2011-0852, CVE-2011-0870,
CVE-2011-0876, CVE-2011-0877, CVE-2011-0879, CVE-2011-0882,
CVE-2011-2230, CVE-2011-2231, CVE-2011-2232, CVE-2011-2244, CVE-2011-2257,
CVE-2011-0883
|
Fusion Middleware and 10.1.0.5 Database Patch
See Note
1301699.1, How the SSL/TLS Renegotiation Protocol Change Affects Oracle
HTTP Server
|
Single Sign-On Repository
|
Patch 12375695
|
Released April 2011
|
|
Middle Tier home (Oracle Wireless)
|
Patch 9774786
|
Released July 2010
|
|
Discoverer Admin/Desktop home
|
Patch 7277413
|
Released October 2008
|
|
Discoverer Plus or Viewer / Middle-tier home
|
Patch 10233659
|
Released January 2011
|
|
JDeveloper home
|
Patch 7573867
|
Released January 2009
|
Apply to JDeveloper homes only
|
JInitiatorFoot 1
|
Patch 5882294
|
Released July 2007
|
JInitiator 1.3.1.28 or any later release
This patch also applies to Oracle Forms as
JInitiator is installed by default
|
OC4J home (Standalone)
|
Patch 12434221
|
CVE-2011-0883
|
|
Oracle Forms home
|
Patch 9593176
|
Released January 2011
|
|
Portal 10.1.4.2 Repository home
|
Patch 9386084
|
Released April 2010
|
If you are using Portal 10.1.4.2 and Database 11.x
then install Patch 9677027 instead of Patch 9386084
|
Portal 10.1.2.3 Repository home
|
Patch 9386107
|
Released April 2010
|
|
Portal 10.1.2.3/10.1.4.2 middle tier home
|
Patch 11716853
|
Released April 2011
|
|
Table 44 describes the patch information
for Oracle Identity Management 10.1.4.3.
Table 44 Patch
Information for Oracle Identity Management 10.1.4.3
Table 45 describes the available patches
for Oracle Identity Management 10.1.4.3.
For each home
you are about to administer, find the appropriate patches based on the
components installed in that home. Then, apply those patches in the order
listed. For information about the different types of installations, see My
Oracle Support Note 405972.1, Oracle
Application Server 10g Examples for Critical Patch Updates.
Table 45 Patch
Availability for Oracle Identity Management 10.1.4.3
Oracle
Identity Management 10.1.4.3
|
Patches
|
Advisory
Number
|
Comments
|
Oracle
Database home
|
See Section 3.1.3, "Oracle Database"
|
See Section 3.1.3, "Oracle Database"
|
Separate
Database homes only
|
Oracle
Identity Management 10.1.4.3 home
|
UNIX: Patch 12434134
Microsoft Windows (32-Bit): Patch 12434141
Microsoft Windows Itanium (64-Bit): Patch 12434144
|
CVE-2011-0816, CVE-2011-0822, CVE-2011-0830,
CVE-2011-0831, CVE-2011-0848, CVE-2011-0852, CVE-2011-0870,
CVE-2011-0876, CVE-2011-0877, CVE-2011-0879, CVE-2011-0882,
CVE-2011-2230, CVE-2011-2231, CVE-2011-2232, CVE-2011-2244,
CVE-2011-2257, CVE-2011-0883
|
Fusion Middleware and 10.1.0.5 Database Patch
See Note 1301699.1, How the SSL/TLS
Renegotiation Protocol Change Affects Oracle HTTP Server
|
Oracle
Identity Management 10.1.4.3 home
|
Patch 9679955
|
Released October 2010
|
Oracle Identity Management patch
|
Table 46 describes the patch information
for Oracle Identity Management 10.1.4.0.1.
Table 46 Patch
Information for Oracle Identity Management 10.1.4.0.1
Table 47 describes the available patches
for Oracle Identity Management 10.1.4.0.1.
For each home
you are about to administer, find the appropriate patches based on the
components installed in that home. Then, apply those patches in the order
listed. For information about the different types of installations, see My
Oracle Support Note 405972.1, Oracle
Application Server 10g Examples for Critical Patch Updates.
Table 47 Patch
Availability for Oracle Identity Management 10.1.4.0.1
Oracle
Identity Management 10.1.4.0.1
|
Oracle
Solaris x86 (32-Bit)
|
Advisory
Number
|
Comments
|
Oracle
Database home
|
See Section 3.1.3, "Oracle Database"
|
See Section 3.1.3, "Oracle Database"
|
Separate
Database homes only
|
Oracle
Identity Management 10.1.4.0.1 home
|
Patch 12434134
|
CVE-2011-0816, CVE-2011-0822, CVE-2011-0830,
CVE-2011-0831, CVE-2011-0848, CVE-2011-0852, CVE-2011-0870,
CVE-2011-0876, CVE-2011-0877, CVE-2011-0879, CVE-2011-0882,
CVE-2011-2230, CVE-2011-2231, CVE-2011-2232, CVE-2011-2244,
CVE-2011-2257, CVE-2011-0883
|
Fusion Middleware and 10.1.0.5 Database Patch
See Note 1301699.1, How the
SSL/TLS Renegotiation Protocol Change Affects Oracle HTTP Server
|
Oracle
Identity Management 10.1.4.0.1 home
|
Patch 9679932
|
Released July 2010
|
Oracle Identity Management patch
|
Table 48 describes the minimum product
requirements for Oracle GoldenGate Veridata. The CPU security vulnerabilities
are fixed in the listed release and later releases. The Oracle GoldenGate
Veridata downloads and installation instructions can be found at http://www.oracle.com/technetwork/middleware/goldengate/overview/index.html
Table 48
Minimum Product Requirements for Oracle GoldenGate Veridata
Table 49 describes the available patches
for Oracle Hyperion BI+, based on release.
Table 49 Patch
Availability for Oracle Hyperion BI+
Table 50 describes the available patches
for Oracle Identity Manager.
Table 50 Patch
Availability for Oracle Identity Manager
Table 51 describes the Critical Patch
Update availability for Oracle JRockit.
Oracle JRockit
R28.1.4 and R27.7.1 include fixes for all security advisories that have
been released through CPUJul2011.
Table 51
Critical Patch Update Availability for Oracle JRockit
Table 52 describes the available patches
for Oracle Outside in Technology.
Table 52 Patch
Availability for Oracle Outside In Technology
Table 53 describes the Critical Patch
Update availability for Oracle WebLogic Server. This lists the WebLogic
Server releases that are part of Fusion Middleware 11gR1. For information
about older releases, see Note 1323601.1, Patch
Availability Document for Oracle BEA Releases.
Table 53
Critical Patch Update Availability for Oracle WebLogic Server
Table 54 describes the Patch Set Update
availability for Oracle WebLogic Server.
Table 54 Patch
Set Update Availability for Oracle WebLogic Server
Table 55 describes the Critical Patch
Update availability for Oracle WebLogic Server Plug-ins. For more information,
see My Oracle Support Note 1111903.1, WebLogic Server
Web Server Plug-In Support
Table 55
Critical Patch Update Availability for Oracle WebLogic Server Plug-ins
This section contains the following:
·
Section 3.3.1, "Patch Availability Information for
Oracle Enterprise Manager Grid Control"
·
Section 3.3.2, "Patch Availability for Oracle
Enterprise Manager Grid Control 11.1.0.1"
·
Section 3.3.3, "Patch Availability for Oracle
Enterprise Manager Grid Control 10.2.0.5"
·
Section 3.3.4, "Patch Availability for Oracle
Enterprise Manager Grid Control 10.1.0.6"
·
Section 3.3.5, "Patch Availability for Oracle Real
User Experience Insight,"
For CPUJul2011
patch information, see Section 3.3, "Oracle Enterprise Manager." For information on identifying
which patches are recommended for the OMS and Agent homes, see My Oracle
Support Note 1337560.1, Recommended
Patches for Enterprise Manager Grid Control.
The Critical
Patch Updates for Enterprise Manager Grid Control are not inclusive of the
Oracle Database and Oracle Fusion Middleware middle tier patches. Since
these products are bundled with Enterprise Manager Grid Control, the
Repository (Oracle Database) and Oracle Management Server (Oracle Fusion
Middleware middle tier) should be patched separately, depending on which
versions are installed. For more information, see My Oracle Support Note 412431.1, Grid Control
Certification Matrix.
Table 56 describes patch information for
Oracle Enterprise Manager Grid Control 11.1.0.1.
Table 56 Patch
Information for Oracle Enterprise Manager Grid Control 11.1.0.1
Table 57 describes the available patches
for Oracle Enterprise Manager Grid Control 11.1.0.1.
Table 57 Patch
Set Update Availability for Oracle Enterprise Manager Grid Control 11.1.0.1
Table 58 describes patch information for
Oracle Enterprise Manager Grid Control 10.2.0.5.
Table 58 Patch
Information for Oracle Enterprise Manager Grid Control 10.2.0.5
Table 59 describes the available patches
for Oracle Enterprise Manager Grid Control 10.2.0.5.
Table 59 Patch
Availability for Oracle Enterprise Manager Grid Control 10.2.0.5
Table 60 describes patch information for
Oracle Enterprise Manager Grid Control 10.1.0.6.
Table 60 Patch
Information for Oracle Enterprise Manager Grid Control 10.1.0.6
Table 61 describes the available patches
for Oracle Enterprise Manager Grid Control 10.1.0.6.
For each home
you are about to administer, find the appropriate patches based on the
components installed in that home. Then, apply those patches in the order
listed.
Table 61 Patch
Availability for Oracle Enterprise Manager Grid Control 10.1.0.6
Table 62 describes the available patches
for Oracle Real User Experience Insight.
Table 62 Patch
Availability for Oracle Real User Experience Insight
This section contains the following:
·
Section 3.4.1, "Patch Availability Information for
Oracle Collaboration Suite"
Oracle
Collaboration Suite homes contain database and application server homes.
For more information on Oracle Database and Oracle Fusion Middleware
Critical Patch Updates that apply to Oracle Collaboration Suite homes, see
My Oracle Support Note 559534.1 Applying
Critical Patch Updates to Collaboration Suite 10g.
Table 63 describes the available patches
for Oracle Collaboration Suite.
For each home
you are about to administer, find the appropriate patches based on the
components installed in that home. Then, apply those patches in the order
listed.
Table 63 Patch
Availability for Oracle Collaboration Suite
Oracle
Collaboration Suite
|
UNIX
|
Microsoft
Windows (32-Bit)
|
Advisory
Number
|
Comments
|
Infrastructure
home
|
Patch 6640838
|
Patch 6640838
|
Released January 2010
|
Oracle Universal Installer patch
See Note 565374.1 for information on installing
this patch
|
Infrastructure
home
|
Patch 11842285
|
NA
|
CVE-2011-2240
|
Oracle Universal Installer patch
|
Middle Tier home
|
Patch 6640838
|
Patch 6640838
|
Released January 2010
|
Oracle Universal Installer patch
See Note 565374.1 for information on installing
this patch
|
Middle
Tier home
|
Patch 11842285
|
NA
|
CVE-2011-2240
|
Oracle Universal Installer patch
|
Infrastructure home
|
Patch 12434134
|
Patch 12434141
|
CVE-2011-0816, CVE-2011-0822, CVE-2011-0830,
CVE-2011-0831, CVE-2011-0848, CVE-2011-0852, CVE-2011-0870,
CVE-2011-0876, CVE-2011-0877, CVE-2011-0879, CVE-2011-0882,
CVE-2011-2230, CVE-2011-2231, CVE-2011-2232, CVE-2011-2244,
CVE-2011-2257, CVE-2011-0883
|
|
Oracle Fusion Middleware 10.1.2.3 middle tier home
|
Patch 12434134
|
Patch 12434141
|
CVE-2011-0816, CVE-2011-0822, CVE-2011-0830,
CVE-2011-0831, CVE-2011-0848, CVE-2011-0852, CVE-2011-0870,
CVE-2011-0876, CVE-2011-0877, CVE-2011-0879, CVE-2011-0882,
CVE-2011-2230, CVE-2011-2231, CVE-2011-2232, CVE-2011-2244,
CVE-2011-2257, CVE-2011-0883
|
|
Oracle Fusion Middleware 10.1.2.3 middle tier home
(UIX)
|
Patch 9373917
|
Patch 9373917
|
Released January 2011
|
|
Portal 10.1.4.2 Repository home
|
Patch 9386084
|
Patch 9386084
|
Released April 2010
|
|
Portal 10.1.2.3 Repository home
|
Patch 9386107
|
Patch 9386107
|
Released April 2010
|
|
Portal 10.1.2.3/10.1.4.2 middle tier home
|
Patch 11716853
|
Patch 11716853
|
CVE-2011-0798
|
|
Collaboration Suite 10g Real-Time Collaboration home
|
Patch 6130704
|
Patch 6130704
|
Released July 2007
|
|
Collaboration Suite 10g Workspaces home
|
Patch 6127414
|
Patch 6127414
|
Released January 2009
|
For more information, see My Oracle Support Note 406284.1
|
This section
contains the following:
·
Section 3.5.1, "Oracle Opatch"
Table 64 describes the minimum product
requirements for Oracle OPatch. The CPU security vulnerabilities are fixed
in the listed release and later releases. The Oracle OPatch downloads can
be found at Patch 6880880.
Table 64 Minimum Product Requirements for Oracle OPatch
Table 65 describes the final patch
history.
Table 65 Final
Patch History
The following
documents provide additional information about Critical Patch Updates:
·
My Oracle Support Note 1314535.1, Announcing
Exalogic PSUs (Patch Set Updates)
·
My Oracle Support Note 1306505.1, Announcing
Oracle WebLogic Server PSUs (Patch Set Updates)
·
My Oracle Support Note 1323607.1, Critical Patch
Update July 2011 Database Patch Security Vulnerability Molecule Mapping
·
My Oracle Support Note 1323600.1, Critical Patch
Update July 2011 Known Issues for Oracle Enterprise Manager Grid Control.
·
My Oracle Support Note 1323599.1, Critical Patch
Update July 2011 Database Known Issues.
·
My Oracle Support Note 1323598.1, Critical Patch
Update July 2011 Oracle Fusion Middleware Known Issues.
·
My Oracle Support Note 1227443.1, Patch Set
Updates Known Issues Notes
·
My Oracle Support Note 961735.1, Oracle Identity
Management 10g (10.1.4) Support Status and Alerts
·
My Oracle Support Note 882604.1, Changes to
Critical Patch Update and Patch Set Update Platform Release Plans
·
My Oracle Support Note 854428.1, Patch Set
Updates for Oracle Products
·
My Oracle Support Note 605795.1, Introduction to
catbundle.sql.
·
My Oracle Support Note 605398.1, How To Find The
Version Of The Main EM Components.
·
My Oracle Support Note 559534.1, Applying
Critical Patch Updates to Collaboration Suite 10g.
·
My Oracle Support Note 438314.1, Critical Patch
Update - Introduction to Database n-Apply CPU Patches.
·
My Oracle Support Note 415222.1, Steps to
Maintain Oracle Application Server 10g Release 2 (10.1.2)
·
My Oracle Support Note 412431.1, Grid Control
Certification Matrix.
·
My Oracle Support Note 405972.1, Oracle
Application Server 10g Examples for Critical Patch Updates.
·
My Oracle Support Note 209768.1, Database, FMW,
EM Grid Control, and OCS Software Error Correction Support Policy.
·
My Oracle Support Note 161549.1, Oracle Database
Server and Networking Patches for Microsoft Platforms.
Table 66 describes the modification
history for this document.
Table 66
Modification History
For
information about Oracle's commitment to accessibility, visit the Oracle
Accessibility Program website at http://www.oracle.com/pls/topic/lookup?ctx=acc&id=docacc.
Access to
Oracle Support
Oracle
customers have access to electronic support through My Oracle Support. For
information, visit http://www.oracle.com/pls/topic/lookup?ctx=acc&id=info or visit http://www.oracle.com/pls/topic/lookup?ctx=acc&id=trs if you are hearing impaired.
Patch Set
Update and Critical Patch Update July 2011 Availability Document
Copyright ©
2011, Oracle and/or its affiliates. All rights reserved.
|