微信公众号:云库管    www.yunDBA.com

北京云库管科技有限公司 (内部培训资料) 返回上级

 

PDF文档下载

 

Patch Set Update and Critical Patch Update October 2012 Availability Document (Doc ID 1477727.1)

To Bottom


PURPOSE

This document defines the patches and minimum releases for the Database Product Suite, Fusion Middleware Product Suite, Exalogic, and Enterprise Manager Suite Critical Patch Updates and Patch Set Updates released on October 16, 2012.

DETAILS

Patch Set Update and Critical Patch Update October 2012 Availability Document

 

 

My Oracle Support Note 1477727.1

Released October 16th, 2012

This document contains the following sections:

·         Section 1, "Overview"

·         Section 2, "What's New in October 2012"

·         Section 3, "Patch Availability for Oracle Products"

·         Section 4, "Final Patch History"

·         Section 5, "Sources of Additional Information"

·         Section 6, "Modification History"

·         Section 7, "Documentation Accessibility"

1 Overview

Oracle provides quarterly Security Patch Updates (SPU) to address security vulnerabilities, and Patch Set Updates (PSU) to address proactive, critical fixes and security vulnerabilities. The security vulnerabilities addressed are announced in the Advisory for October 2012, available at http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html.

This document lists the Oracle Database, Fusion Middleware and Enterprise Manager SPU and PSU patches for product releases under error correction. The October 2012 release supersedes earlier Critical Patch Updates and Patch Set Updates for the same product releases. This document is subject to continual update after the initial release, and the changes are listed in Section 6, "Modification History." If you print this document, check My Oracle Support to ensure you have the latest version.

This section contains the following:

·         Section 1.1, "How To Use This Document"

·         Section 1.2, "Terminology in the Tables"

·         Section 1.3, "On-Request Patches"

·         Section 1.4, "Oracle Database Security Patch Updates and Patch Set Updates"

1.1 How To Use This Document

The following steps explain how to use this document.

Step 1   Assess your Environments

Determine the Oracle product suites and products and their release numbers for each of your environments.

Step 2   Read Important Announcements

Review Section 2, "What's New in October 2012," as it lists documentation and packaging changes along with important announcements such as upcoming final patches.

Step 3   Determine Patches to be Applied

For each environment, determine which patches need to be applied by using the tables in Section 3, "Patch Availability for Oracle Products." There is one availability table for each product suite release, such as Oracle Database 11.1.0.7, Oracle Fusion Middleware 11.1.1.5.0, and Enterprise Manager Grid Control 10.2.0.5

·         The table lists the patches to be applied either to the product or to the appropriate product Oracle homes that are associated with the product suite

·         The patches are listed in the order released, with newest patches listed first

·         For some patches, multiple Oracle homes are listed. Apply the patch to all of the homes indicated that are applicable to your environment and only to the listed Oracle homes

·         The table lists only product releases that are under Premier Support or Extended Support and are under error correction as defined in My Oracle Support Note 209768.1, Database, FMW, EM Grid Control, and OCS Software Error Correction Support Policy. CPU and PSU patches are provided only for these releases. If you do not see the release that you have installed, then check Table 121, "Final Patch History" and contact Oracle Support for further assistance

·         Patches that include security vulnerabilities announced in the current quarter's CPU Advisory, list the vulnerability CVE numbers in the Advisory Number column. If you are interested in the risk matrix for the vulnerabilities fixed in the patch, then see the CPU Advisory at http://www.oracle.com/technetwork/topics/security/alerts-086861.html. For patches that are listed from previous quarterly releases, the column will indicate 'Released MMM YYYY'. You can easily find which Critical Patch Updates are new by searching for the string 'CVE' in the tables

·         When a section is referenced in a table, follow the link to determine which patches to install. For example, when Section 3.2.4, "Oracle Database" is referenced, determine the Oracle Database release that is installed, and find the patches to apply in the table for that Oracle Database release in Section 3.2.4, "Oracle Database."

Step 4   Apply the Patches

Download the patches, review the READMEs, and apply the patches according to the instructions.

1.2 Terminology in the Tables

The following terminology is used in this patch availability document and in the subsequent tables.

·         BP Bundle Patch. An iterative, cumulative patch that is issued between patch sets. Bundle patches usually include only fixes, but some products may include minor enhancements.

·         CPU Critical Patch Update patch. Prior to October 2012, Security Patch Update (SPU) patches were called Critical Patch Update (CPU) patches. For patches that were previously released as CPU patches, this Patch Availability Document will continue to reference them as CPUs.

·         NA Not Applicable. The patch is not planned for this platform and release version combination. This may be due to several reasons including:

1.  The release version is not available on this platform.

2.  The release version does not fall under Critical Patch Update release policies. Refer to My Oracle Support Note 209768.1, Database, FMW, EM Grid Control, and OCS Software Error Correction Support Policy.

·         OR On-Request. The patch may be made available through the On-Request program.

·         PSU Patch Set Update. A quarterly patch that contains the most critical fixes for the applicable product, allowing customers to apply one patch to avoid many problems.

·         SPU Security Patch Update. An iterative, cumulative patch consisting of security fixes. Formerly known as a Critical Patch Update. Note that Oracle's program for quarterly release of security fixes continues to be called the Critical Patch Update. Patches released as part of this program may be Patch Set Updates, Security Patch Updates, and Bundle Patches. Regardless of the patch type, the patches are cumulative.

1.3 On-Request Patches

Oracle does not release proactive patches for platform-version combinations that have fewer than 10 downloads in the prior Critical Patch Update release. Oracle will deliver patches for these historically inactive platform-version combinations when requested.

The following guidelines describe how to initiate an on-request (OR) patch.

A request may be made:

·         At any time. However, a patch for a specific quarterly release, such as CPUOct2012, cannot be requested. Depending on when the request is received and processed, either the patch for the current quarterly release or the next quarterly release will be provided. Your Service Request (SR) will provide you the planned availability date for the patch.

·         As long as the version is in either Premier Support or Extended Support. Once the final patch for the version has been released, an OR can be requested for up to 2 weeks after the release date. For example, if a product release is under Extended Support through the release of CPUJan2013 on January 15, 2013, then you can file a request for the product release through January 29, 2013.

·         For a platform-version combination if the product or patch set is released on a platform after a quarterly release date. Oracle will provide the next patch for that platform-version combination, however you may request the current patch by following the on-request process. For example, if a patch is released for a platform on August 1, 2012, Oracle will provide the CPUOct2012 patch for that platform. You may request a CPUJul2012 patch for the platform, and Oracle will review the request and determine whether to provide CPUJul2012 or CPUOct2012.

A patch that is marked as on-request (OR) may already have been requested by another customer and be available on My Oracle Support. Before you file a Service Request (SR), check on My Oracle Support to see if the patch is already available for your platform.

1.4 Oracle Database Security Patch Updates and Patch Set Updates

The Database Security Patch Updates and Patch Set Updates that are released each quarter contain the same security fixes. However, they use different patching mechanisms, and Patch Set Updates include both security and recommended bug fixes. Consider the following guidelines when you are deciding to apply Patch Set Updates instead of Security Patch Updates:

·         Security Patch Updates are applied only on the base release version, for example 10.2.0.4.0

·         Patch Set Updates can be applied on the base release version or on any earlier Patch Set Update. For example, 11.1.0.7.2 can be applied on 11.1.0.7.1 and 11.1.0.7.0

·         Once a Patch Set Update has been applied, the recommended way to obtain future security content is to apply subsequent Patch Set Updates. Reverting from an applied Patch Set Update to the Security Patch Update, while technically possible, requires significant time and effort, and therefore, is not advised. You would need to determine which individual, non-security patches that are included in the Patch Set Update are pertinent to your deployment, and then apply them after installing the Security Patch Update.

·         Applying a Security Patch Update on an installation with an installed Patch Set Update is not supported

For more information on Patch Set Updates, see My Oracle Support Note 854428.1, Patch Set Updates (PSUs) for Oracle Products.

2 What's New in October 2012

This section describes important changes in October 2012:

·         Section 2.1, "Patching Implications for CVE-2012-3137 and CVE-2012-3151"

·         Section 2.2, "New Patch Nomenclature for Oracle Products"

·         Section 2.3, "Oracle Security Alert for CVE-2012-3132 Included in CPUOct2012 Database Patches"

·         Section 2.4, "Patch Set Update (PSU) Package Improvement - Composite Patches"

·         Section 2.5, "Oracle Database 10g R2 Patches for HP OpenVMS Alpha and Itanium"

·         Section 2.6, "Oracle Database 10g R2 Patches for IBM z/OS on System z"

·         Section 2.7, "Final Patch Information (Error Correction Policies)"

·         Section 2.8, "New Minimum Product Requirements for CPUOct2012"

·         Section 2.9, "Enterprise Manager Grid Control 10.2.0.5 Critical Patch Advisory Recommendations"

·         Section 2.10, "Post Release CPU and PSU Patches"

2.1 Patching Implications for CVE-2012-3137 and CVE-2012-3151

Patches have been released as part of the October 2012 CPU program to include fixes to protect against vulnerability CVE-2012-3137 and CVE-2012-3151.

CVE-2012-3137

This vulnerability affects database user accounts using SHA-1-based password verifiers for authentication. SHA-1-based password verifiers are also referred to as “11G” password versions. Database user accounts using a DES-based password verifier for authentication are unaffected. DES-based password verifiers are also referred to as “10G” password versions.

For most deployments, patching is only necessary for affected database servers for systems to be protected and to continue to function.

For a limited number of deployments, all Database clients and JDBC clients (including WebLogic Server, Fusion Middleware, Enterprise Manager, etc.) must be patched along with the Database Server; otherwise the un-patched clients will fail to connect to a patched server.

Before installing patches that address CVE-2012-3137, customers must review carefully My Oracle Support Note 1493990.1, Patching for CVE-2012-3137.

CVE-2012-3151

CVE-2012-3151 vulnerability affects Database servers and client-only installations for versions 11.2.0.3, 11.2.0.2, 11.1.0.7, 10.2.0.5 and 10.2.0.4. It does not affect Instant Client installations for any version.

Customers are recommended to apply the applicable patches to their systems to address vulnerability CVE-2012-3151.

2.2 New Patch Nomenclature for Oracle Products

Beginning October 2012, Critical Patch Update (CPU) patches are now called Security Patch Update (SPU) patches. The patches continue to be released as part of the overall Oracle Critical Patch Update (CPU) Program. For more information, see My Oracle Support Note 1430923.1, New Patch Nomenclature for Oracle Products.

For patches that were previously released as CPU patches, this Patch Availability Document will continue to reference them as CPUs. New patches will use the new nomenclature, Security Patch Update (SPU).

2.3 Oracle Security Alert for CVE-2012-3132 Included in CPUOct2012 Database Patches

CPUOct2012 now includes Oracle Security Alert for CVE-2012-3132 as part of the database patches. CPUOct2012 supersedes the Oracle Security Alert for CVE-2012-3132.

2.4 Patch Set Update (PSU) Package Improvement - Composite Patches

Both 11.2.0.2 (starting with 11.2.0.2.7) and 11.2.0.3 (starting with 11.2.0.3.2) PSUs are packaged as composite patches. Composite patch improvements include decreased patch installation time, and reduced need to roll back previously applied overlay patches. With the new composite patch format, it is possible for overlay patches provided on earlier PSUs to co-exist with the new PSU that is being installed. For example, Oracle Database 11.2.0.2.6 PSU overlay patches do not need to be rolled back and replaced if they do not conflict with the new content in Database 11.2.0.2.7 PSU. For more information, see My Oracle Support Note 1376691.1.

2.5 Oracle Database 10g R2 Patches for HP OpenVMS Alpha and Itanium

Oracle released Database 10.2.0.5 Patch Set for HP OpenVMS Alpha and Itanium on October 31st, 2012. Both versions can be downloaded from My Oracle Support Patch 8202632.

The PSU 10.2.0.5.9 Patch 14275629 has also been released to include all content up to and including Database PSU 10.2.0.5.9, both security and non-security fixes.

CPUJan2013 will be the final release of the 10.2.0.4 PSU for both HP OpenVMS Alpha and Itanium.

2.6 Oracle Database 10g R2 Patches for IBM z/OS on System z

Oracle released Database 10.2.0.5 Bundle Patch 1 for IBM z/OS on System z on October 30th, 2012. It can be downloaded from My Oracle Support Patch 14798451.

The 10.2.0.5 Bundle Patch 1 for IBM z/OS on System z includes all Database PSU 10.2.0.5.9 content, both security and non-security fixes.

CPUJan2013 will be the final release of the 10.2.0.3 SPU patch for IBM z/OS on System z.

2.7 Final Patch Information (Error Correction Policies)

The Final patch is the last CPU/PSU release for which the product release is under error correction. Final patches for upcoming releases, as well as newly scheduled final patches, are listed in the following sections.

Final Patches scheduled for October 2012:

·         Oracle AquaLogic Interaction Logging Utilities 6.0

·         Oracle AquaLogic Interaction Logging Utilities 1.0

·         Oracle COREid 10.1.4.3

·         Oracle Secure Backup 10.3.0.3

·         Oracle Single Sign-On/DAS 10.1.4.3

Final patches scheduled for January 2013:

·         Oracle Business Intelligence Enterprise Edition 11.1.1.5.0

·         Oracle Business Intelligence Publisher 11.1.1.5.0

·         Oracle Complex Event Processing and WebLogic Event Server 11.1.1.4.0

·         Oracle Database 10.2.0.4 for HP Open VMS-Alpha, and VMS-Itanium

·         Oracle Database 10.2.0.3 for IBM z/OS on System z

·         Oracle Event Processing 11.1.1.4.0

·         Oracle FatWire Content Server (including Satellite Server) 7.5

·         Oracle FatWire Content Server (including Satellite Server) 7.0.3

·         Oracle FatWire Content Server (including Satellite Server) 7.0.2

·         Oracle FatWire Content Server (including Satellite Server) 7.0.1

·         Oracle FatWire Content Server (including Satellite Server) 7.0

·         Oracle FatWire Content Server (including Satellite Server) 6.3.x

·         Oracle FatWire Content Server (including Satellite Server) 6.2

·         Oracle FatWire Content Server (including Satellite Server) 6.1

·         Oracle Fusion Middleware 11.1.1.5.0

·         Oracle Fusion Middleware 11.1.1.4.0 for Portal, Forms, Reports and Discoverer

·         Oracle Map Viewer 11.1.1.5.0

Newly Scheduled final patches:

·         Oracle Database 11.2.0.2, October 2013

For additional final patch history information, see Table 121. For information on the error correction support policy for patches, refer to My Oracle Support Note 209768.1, Database, FMW, EM Grid Control, and OCS Software Error Correction Support Policy.

2.8 New Minimum Product Requirements for CPUOct2012

The following is new for CPUOct2012:

·         The new minimum version for Oracle Database Appliance is 2.4.0.0.0

2.9 Enterprise Manager Grid Control 10.2.0.5 Critical Patch Advisory Recommendations

In Enterprise Manager Grid Control 10.2.0.5, Critical Patch Advisory recommendations are displayed through the Deployments page in the Grid Control Console. As of July 1, 2013, these CPU recommendations will no longer be available through the Enterprise Manager 10g console. For more information, see My Oracle Support Note 1490312.1.

2.10 Post Release CPU and PSU Patches

The following are the planned release dates for the CPU and PSU patches that have been delayed. This section will be updated as the patches are made available.

·         Database SPU 11.2.0.2 for IBM: Linux on System Z

Available: 19-October-2012

·         Database PSU 10.2.0.4.12 for Apple Mac OS X

Available: 8-November-2012

·         Oracle Database Appliance 2.4.0.0.0

Available: 2-November-2012

3 Patch Availability for Oracle Products

This section contains the following:

·         Section 3.1, "Oracle Collaboration"

·         Section 3.2, "Oracle Database"

·         Section 3.3, "Oracle Enterprise Manager"

·         Section 3.4, "Oracle Fusion Middleware"

·         Section 3.5, "Tools"

3.1 Oracle Collaboration

This section contains the following:

·         Section 3.1.1, "Patch Availability Information for Oracle Collaboration Suite"

3.1.1 Patch Availability Information for Oracle Collaboration Suite

Oracle Collaboration Suite homes contain database and application server homes. For more information on Oracle Database and Oracle Fusion Middleware Critical Patch Updates that apply to Oracle Collaboration Suite homes, see My Oracle Support Note 559534.1 Applying Critical Patch Updates to Collaboration Suite 10g.

Table 1 describes the available patches for Oracle Collaboration Suite.

Table 1 Patch Availability for Oracle Collaboration Suite

Product Home

UNIX

Microsoft Windows (32-Bit)

Advisory Number

Comments

Infrastructure home

Oracle Fusion Middleware 10.1.2.3 middle tier home

CPU Patch 6640838

CPU Patch 6640838

Released January 2010

Oracle Universal Installer patch

See Note 565374.1 for information on installing this patch

Infrastructure home

Oracle Fusion Middleware 10.1.2.3 middle tier home

CPU Patch 11842285

NA

Released July 2011

Oracle Universal Installer patch

Infrastructure home

Oracle Fusion Middleware 10.1.2.3 middle tier home

CPU Patch 12837860

CPU Patch 12837864

Released October 2011

 

Oracle Fusion Middleware 10.1.2.3 middle tier home

CPU Patch 9373917

CPU Patch 9373917

Released January 2011

UIX

Portal 10.1.4.2 Repository home

CPU Patch 9386084

CPU Patch 9386084

Released April 2010

 

Portal 10.1.2.3 Repository home

CPU Patch 9386107

CPU Patch 9386107

Released April 2010

 

Portal 10.1.2.3/10.1.4.2 middle tier home

CPU Patch 11716853

CPU Patch 11716853

Released April 2011

 

Collaboration Suite 10g Real-Time Collaboration home

CPU Patch 6130704

CPU Patch 6130704

Released July 2007

 

Collaboration Suite 10g Workspaces home

CPU Patch 6127414

CPU Patch 6127414

Released January 2009

For more information, see My Oracle Support Note 406284.1

3.2 Oracle Database

This section contains the following:

·         Section 3.2.1, "Oracle APEX Listener"

·         Section 3.2.2, "Oracle Application Express"

·         Section 3.2.3, "Oracle Audit Vault"

·         Section 3.2.4, "Oracle Database"

·         Section 3.2.5, "Oracle Database Appliance"

·         Section 3.2.6, "Oracle Fusion Middleware Utilities for Oracle Databases"

·         Section 3.2.7, "Oracle Secure Backup"

·         Section 3.2.8, "Oracle Secure Enterprise Search"

·         Section 3.2.9, "Oracle TimesTen"

·         Section 3.2.10, "Oracle Workflow Server"

3.2.1 Oracle APEX Listener

Table 2 describes the Error Correction information for Oracle APEX Listener 1.1.4.

Table 2 Error Correction information for Oracle APEX Listener 1.1.4

Patch Information

1.1.4

Comments

Final Patch

-

 

Table 3 describes the minimum product requirements for Oracle APEX Listener. Critical Patch Update security vulnerabilities are fixed in the listed releases. For Oracle APEX Listener downloads and installation instructions, see http://www.oracle.com/technetwork/developer-tools/apex-listener/downloads/index.html.

Table 3 Minimum Product Requirements for Oracle APEX Listener

Component

Release

Advisory Number

Comments

Oracle APEX Listener

1.1.4

Released July 2012

 

3.2.2 Oracle Application Express

Table 4 describes the minimum product requirements for Oracle Application Express. Critical Patch Update security vulnerabilities are fixed in the listed releases. For Oracle Application Express downloads and installation instructions, see http://www.oracle.com/technology/products/database/application_express/download.html.

Table 4 Minimum Product Requirements for Oracle Application Express

Component

Release

Advisory Number

Comments

Oracle Application Express

4.1.1.00.23

Released April 2012

 

3.2.3 Oracle Audit Vault

Table 5 describes the Error Correction information for Oracle Audit Vault.

Table 5 Error Correction information for Oracle Audit Vault

Patch Information

10.3

10.2.3.2

Comments

Final Patch

October 2016

April 2013

 

Table 6 describes the available patches for Oracle Audit Vault 10.3.0.0.

Table 6 Patch Availability for Oracle Audit Vault 10.3.0.0

Product Home

Patch

Advisory Number

Comments

Oracle Audit Vault Embedded Database 11.2.0.3 for Server and Agent home

See Section 3.2.4.2, "Oracle Database 11.2.0.3"

See Section 3.2.4.2, "Oracle Database 11.2.0.3"

 

Agent home

CPU Patch 13894921 and

CPU Patch 13705483

Released April 2012

Standalone OC4J 10.1.3.4 Patch Set (Special OPatch needed, see README)

OC4J 10.1.3.4 one-off patch (Special OPatch needed, see README)

Server home

CPU Patch 13705483

Released April 2012

OC4J 10.1.3.4 one-off patch (Special OPatch needed, see README)

Table 7 describes the available patches for Oracle Audit Vault 10.2.3.2.

Table 7 Patch Availability for Oracle Audit Vault 10.2.3.2

Product Home

Patch

Advisory Number

Comments

Oracle Audit Vault Embedded Database 10.2.0.4 for Server and Agent home

See Section 3.2.4.6, "Oracle Database 10.2.0.4"

See Section 3.2.4.6, "Oracle Database 10.2.0.4"

 

Server and Agent home

CPU Patch 13705483

Released April 2012

OC4J 9.0.4.1 one-off patch

Server and Agent home

CPU Patch 10240229

Released January 2011

Audit Vault 10.2.3.2 Bundle Patch 3 Patch 10240229 or later

3.2.4 Oracle Database

This section contains the following:

·         Section 3.2.4.1, "Patch Availability for Oracle Database"

·         Section 3.2.4.2, "Oracle Database 11.2.0.3"

·         Section 3.2.4.3, "Oracle Database 11.2.0.2"

·         Section 3.2.4.4, "Oracle Database 11.1.0.7"

·         Section 3.2.4.5, "Oracle Database 10.2.0.5"

·         Section 3.2.4.6, "Oracle Database 10.2.0.4"

·         Section 3.2.4.7, "Oracle Database 10.2.0.3"

3.2.4.1 Patch Availability for Oracle Database

For Oracle Database 10.2.0.4 and later releases, customers have the option to install the Security Patch Update (SPU) or the Patch Set Update (PSU). Both patch types are cumulative patches. The PSU includes the security vulnerability bug fixes, as well as additional non-security bug fixes recommended by Oracle. For more information on PSU patches, see My Oracle Support Note 854428.1, Patch Set Updates (PSUs) for Oracle Products.

For the Microsoft Windows platforms, Oracle Database patches are released as cumulative patch bundles. You may install the indicated patch or any later bundle in the Database Windows bundle series. The Windows patch bundles include the security vulnerability bug fixes, the PSU recommended non-security bug fixes, and other customer-requested bug fixes.

3.2.4.2 Oracle Database 11.2.0.3

Table 8 describes the Error Correction information for Oracle Database 11.2.0.3.

Table 8 Error Correction information for Oracle Database 11.2.0.3

Patch Information

11.2.0.3

Comments

Final patch

-

 

SPU On-Request platforms

HP-UX PA RISC

IBM: Linux on System Z

32-bit client-only platforms except Linux x86

 

PSU On-Request platforms

32-bit client-only platforms except Linux x86

 

Table 9 describes the available patches for Oracle Database 11.2.0.3.

Table 9 Patch Availability for Oracle Database 11.2.0.3

Product Home

Patch

Advisory Number

Comments

Oracle Database home

Database 11.2.0.3 SPU Patch 14390252, or

Database 11.2.0.3.4 PSU Patch 14275605, or

GI 11.2.0.3.4 PSU Patch 14275572, or

Quarterly Database patch for Exadata - October 2012 11.2.0.3.11 BP Patch 14474780, or

Quarterly Full Stack download for Exadata (October 2012) BP Patch 14621036, or

Microsoft Windows (32-Bit) BP 11 Patch 14613222, or

Microsoft Windows x64 (64-Bit) BP 11 Patch 14613223

CVE-2012-1751, CVE-2012-3132, CVE-2012-3137, CVE-2012-3146, CVE-2012-3151

 

Oracle Database home

CPU Patch 13705478

Released April 2012

OC4J 10.1.3.4 one-off patch (Special OPatch needed, see README)

3.2.4.3 Oracle Database 11.2.0.2

Table 10 describes the Error Correction information for Oracle Database 11.2.0.2.

Table 10 Error Correction information for Oracle Database 11.2.0.2

Patch Information

11.2.0.2

Comments

Final patch

October 2013

 

SPU On-Request platforms

HP-UX PA RISC

IBM: Linux on System Z

32-bit client-only platforms except Linux x86

 

PSU On-Request platforms

32-bit client-only platforms except Linux x86

 

Table 11 describes the available patches for Oracle Database 11.2.0.2.

Table 11 Patch Availability for Oracle Database 11.2.0.2

Product Home

Patch

Advisory Number

Comments

Oracle Database home

Database 11.2.0.2 SPU Patch 14390377, or

Database 11.2.0.2.8 PSU Patch 14275621, or

GI 11.2.0.2.8 PSU Patch 14390437, or

Exadata Database Recommended BP 18 Patch 14461970, or

Microsoft Windows (32-Bit) BP 22 Patch 14672267, or

Microsoft Windows x64 (64-Bit) BP 22 Patch 14672268

CVE-2012-1751, CVE-2012-3132, CVE-2012-3137, CVE-2012-3146, CVE-2012-3151

Before installing listed patches, you must read My Oracle Support Note 1493990.1, Patching for CVE-2012-3137

Oracle Database home

CPU Patch 13705478

Released April 2012

OC4J 10.1.3.4 one-off patch (Special OPatch needed, see README)

3.2.4.4 Oracle Database 11.1.0.7

Table 12 describes the Error Correction information for Oracle Database 11.1.0.7.

Table 12 Error Correction information for Oracle Database 11.1.0.7

Patch Information

11.1.0.7

Comments

Final patch

July 2015

 

SPU On-Request platforms

-

 

PSU On-Request platforms

-

 

Table 13 describes the available patches for Oracle Database 11.1.0.7.

Table 13 Patch Availability for Oracle Database 11.1.0.7

Product Home

Patch

Advisory Number

Comments

Oracle Database home

Database 11.1.0.7 SPU Patch 14390384, or

Database 11.1.0.7.13 PSU Patch 14275623, or

Microsoft Windows (32-Bit) BP 50 Patch 14672312, or

Microsoft Windows x64 (64-Bit) BP 50 Patch 14672313

CVE-2012-1751, CVE-2012-3132, CVE-2012-3137, CVE-2012-3146, CVE-2012-3151

Before installing listed patches, you must read My Oracle Support Note 1493990.1, Patching for CVE-2012-3137

Oracle Database home

CPU Patch 13705478

Released April 2012

OC4J 10.1.3.3 one-off patch

Oracle CRS home

CRS 11.1.0.7.7 PSU Patch 11724953

Released April 2011

Non-security content only

Oracle Database home

CPU Patch 9288120

Released April 2011

Database UIX

For Oracle Secure Enterprise Search 11.1.2.x installations, follow the instructions given in MOS note Note 1359600.1.

Oracle Database home

CPU Patch 10073948

Released April 2011

Enterprise Manager Database Control UIX

Not applicable to Oracle Secure Enterprise Search 11.1.2.x

Oracle Database home

CPU Patch 11738232

Released April 2011

Warehouse Builder

Not applicable to Oracle Secure Enterprise Search 11.1.2.x

3.2.4.5 Oracle Database 10.2.0.5

Table 14 describes the Error Correction information for Oracle Database 10.2.0.5.

Table 14 Error Correction information for Oracle Database 10.2.0.5

Patch Information

10.2.0.5

Comments

Final patch

July 2013

 

SPU On-Request platforms

HP-UX PA-RISC

IBM: Linux on System Z

Linux Itanium

Linux on POWER

 

Database PSU On-Request platforms

-

 

CRS PSU On-Request platforms

HP-UX PA-RISC

IBM: Linux on System Z

Solaris x86-64

 

Table 15 describes the available patches for Oracle Database 10.2.0.5.

Table 15 Patch Availability for Oracle Database 10.2.0.5

Product Home

Patch

Advisory Number

Comments

Oracle Database home

Database 10.2.0.5 SPU Patch 14390396, or

Database PSU 10.2.0.5.9 Patch 14275629, or

IBM z/OS on System z 10.2.0.5 BP1 Patch 14798451, or

Microsoft Windows (32-Bit) BP 19 Patch 14553356, or

Microsoft Windows x64 (64-Bit) BP 19 Patch 14553358, or

Microsoft Windows Itanium (64-Bit) BP 19 Patch 14553357

CVE-2012-1751, CVE-2012-3132, CVE-2012-3137, CVE-2012-3146, CVE-2012-3151

Before installing listed patches, you must read My Oracle Support Note 1493990.1, Patching for CVE-2012-3137

Oracle Database home

CPU Patch 13705478

Released April 2012

OC4J 10.1.3.4 one-off patch (Special OPatch needed, see README)

Oracle Database home

CPU Patch 12536181

Released July 2011

Enterprise Manager Database Control

For HP-UX PA-RISC and HP-UX Itanium platforms only

Oracle Warehouse Builder home

CPU Patch 11738172

Released April 2011

Warehouse Builder

Oracle CRS home

CRS 10.2.0.5.2 PSU Patch 9952245

Released January 2011

Non-security content only

3.2.4.6 Oracle Database 10.2.0.4

Table 16 describes the Error Correction information for Oracle Database 10.2.0.4.

Table 16 Error Correction information for Oracle Database 10.2.0.4

Patch Information

10.2.0.4

Comments

Final patch

July 2013 for Oracle Solaris x86 (32-bit) and Apple Mac OS X

January 2013 for HP Open VMS-Alpha, and VMS-Itanium

July 2011 for all other platforms

 

SPU On-Request platforms

Apple Mac OS X

HP Open VMS-Alpha

HP Open VMS-Itanium

Oracle Solaris x86 (32-bit)

 

PSU On-Request platforms

-

 

Table 17 describes the available patches for Oracle Database 10.2.0.4.

Table 17 Patch Availability for Oracle Database 10.2.0.4

Product Home

Patch

Advisory Number

Comments

Oracle Database home

Database 10.2.0.4 SPU Patch 14390410, or

Database 10.2.0.4.14 PSU Patch 14275630

CVE-2012-3132, CVE-2012-3137, CVE-2012-3146, CVE-2012-3151

Before installing listed patches, you must read My Oracle Support Note 1493990.1, Patching for CVE-2012-3137

10.2.0.4 SPU Patch 14390410 has no platforms available. All platforms other than those listed for On-Request are now out of Error Correction. See July 2011 information in Table 121

10.2.0.4.14 Overlay PSU Patch 14275630 is available only for four platforms. All other platforms are now out of Error Correction. See July 2011 information in Table 121. 10.2.0.4.4 PSU 9352164 is base PSU for 10.2.0.4.14 Overlay PSU

Oracle Database home

CPU Patch 13705478

Released April 2012

OC4J 9.0.4.1 one-off patch

Oracle Database home

CPU Patch 12536167

Released July 2011

Enterprise Manager Database Control

For HP-UX PA-RISC and HP-UX Itanium platforms only

Oracle Database home

CPU Patch 12758181

Released July 2011

Enterprise Manager Database Control UIX

Oracle Database home

CPU Patch 9249369

Released April 2011

Database UIX

Oracle Database home

CPU Patch 9273865

Released April 2011

iSqlPlus UIX

Oracle CRS home

CRS 10.2.0.4.4 PSU Patch 9294403

Released April 2010

Non-security content only

3.2.4.7 Oracle Database 10.2.0.3

Table 18 describes the Error Correction information for Oracle Database 10.2.0.3.

Table 18 Error Correction information for Oracle Database 10.2.0.3

Patch Information

10.2.0.3

Comments

Final patch

January 2013

IBM zSeries (z/OS) only

SPU On-Request platforms

-

 

Table 19 describes the available patches for Oracle Database 10.2.0.3.

Table 19 Patch Availability for Oracle Database 10.2.0.3

Product Home

IBM zSeries (z/OS)

Advisory Number

Comments

Oracle Database home

Database 10.2.0.3 SPU Patch 14390427

CVE-2012-3132, CVE-2012-3137, CVE-2012-3146

Before installing listed patches, you must read My Oracle Support Note 1493990.1, Patching for CVE-2012-3137

Oracle Database home

CPU Patch 13705478

Released April 2012

OC4J 9.0.4.1 one-off patch

3.2.5 Oracle Database Appliance

Table 20 describes the minimum product requirements for Oracle Database Appliance. The CPU security vulnerabilities are fixed in the listed release and later releases. The Oracle Database Appliance downloads and installation instructions can be found at http://www.oracle.com/technetwork/server-storage/engineered-systems/database-appliance/overview/index.html.

Table 20 Minimum Product Requirements for Oracle Database Appliance

Component

Release

Advisory Number

Comments

Oracle Database Appliance

2.4.0.0.0

CVE-2012-1751, CVE-2012-3132, CVE-2012-3137, CVE-2012-3146, CVE-2012-3151

 

3.2.6 Oracle Fusion Middleware Utilities for Oracle Databases

Table 21 lists the patches for Oracle Fusion Middleware components, such as Oracle HTTP Server, which are installed using the Oracle Database Companion CD. For information about Oracle Fusion Middleware 11g, see My Oracle Support Note 1304604.1, Oracle Fusion Middleware 11g Web-Tier FAQ, and Section 3.4.13, "Oracle Fusion Middleware."

Table 21 Patch Availability for Oracle Fusion Middleware Utilities for Oracle Databases

Product Home

Patch

Advisory Number

Comments

Oracle HTTP Server 10.1.2.3 for Oracle 10.2.x Databases

Unix: CPU Patch 12837860

Microsoft Windows (32-Bit): Bundle Patch 12837864

Microsoft Windows (64-Bit): Bundle Patch 12837867

Released October 2011

See My Oracle Support Note 400010.1Steps to Maintain Oracle Database 10.2 Companion CD Home (for Oracle HTTP Server)

3.2.7 Oracle Secure Backup

Table 22 describes the Error Correction information for Oracle Secure Backup.

Table 22 Error Correction information for Oracle Secure Backup

Patch Information

10.4.x

10.3.x

Comments

Final Patch

October 2016

October 2012

 

Table 23 describes the minimum product requirements for Oracle Secure Backup. Critical Patch Update security vulnerabilities are fixed in the listed releases.

Table 23 Minimum Product Requirements for Oracle Secure Backup 10.4.x

Product

Release

Advisory Number

Comments

Oracle Secure backup

10.4.0.2

Released July 2012

 

Table 24 describes the available patches for Oracle Secure Backup.

Table 24 Patch Availability for Oracle Secure Backup 10.3.x

Product Home

Patch

Advisory Number

Comments

Release 10.3.0.3

CPU Patch 14002881

Released July 2012

 

Release 10.3.0.3

CPU Patch 12573094

Released July 2011

 

3.2.8 Oracle Secure Enterprise Search

Table 25 describes Error Correction information for Oracle Secure Enterprise Search.

Table 25 Error Correction information for Oracle Secure Enterprise Search

Patch Information

11.1.2.x

Comments

Final Patch

January 2015

 

Table 26 describes the available patches for Oracle Secure Enterprise Search 11.1.2.x.

Table 26 Patch Availability for Oracle Secure Enterprise Search 11.1.2.x

Product Home

Patch

Advisory Number

Comments

Oracle Database 11.1.0.7

See Section 3.2.4.4, "Oracle Database 11.1.0.7"

See Section 3.2.4.4, "Oracle Database 11.1.0.7"

Database UIX Patch 9288120 requires specific steps to be followed for Secure Enterprise Search customers. See Section 3.2.4.4, "Oracle Database 11.1.0.7"

11.1.2.x

CPU Patch 12875001

CPU Patch 12875006

CPU Patch 12874981

CPU Patch 13718626

CPU Patch 10625676

CPU Patch 13442902

Released October 2011

Released October 2011

Released October 2011

Released April 2012

Released January 2011

Released January 2012

WLS 10.3.2.0 JMS patch

WLS 10.3.2.0 WebServices patch

WLS 10.3.2.0 Security patch

WLS 10.3.2.0 WebApp patch

WLS 10.3.2.0 Core patch

WLS 10.3.2.0 Console patch

3.2.9 Oracle TimesTen

Table 27 describes Error Correction information for Oracle TimesTen.

Table 27 Error Correction information for Oracle TimesTen

Patch Information

11.2.1.x

7.0.x

Comments

Final Patch

April 2017

January 2015

 

Table 28 describes the minimum product requirements for Oracle TimesTen. The CPU security vulnerabilities are fixed in the listed release and later releases.

Table 28 Minimum Product Requirements for Oracle TimesTen

Product

Release

Advisory Number

Comments

Oracle TimesTen 11.2.1.x

11.2.1.6.1

Released July 2010

 

Oracle TimesTen 7.0.x

7.0.6.2.0

Released July 2010

 

3.2.10 Oracle Workflow Server

Table 29 describes Error Correction information for Oracle Workflow Server.

Table 29 Error Correction information for Oracle Workflow Server

Patch Information

2.6.4

Comments

Final Patch

July 2013

 

Table 30 describes the available patches for Oracle Workflow Server.

Table 30 Patch Availability for Oracle Workflow Server

Product Home

Patch

Advisory Number

Comments

Release 2.6.4

CPU Patch 5904430

Released April 2007

 

3.3 Oracle Enterprise Manager

This section contains the following:

·         Section 3.3.1, "Patch Availability for Oracle Enterprise Manager Cloud Control 12c (12.1.0.x),"

·         Section 3.3.2, "Patch Availability for Oracle Database Management Plug-in (12.1.0.x)"

·         Section 3.3.3, "Patch Availability for Oracle Enterprise Manager Grid Control 11g (11.1.0.1)"

·         Section 3.3.4, "Patch Availability for Oracle Enterprise Manager Grid Control 10g (10.2.0.5)"

·         Section 3.3.5, "Oracle Real User Experience Insight"

3.3.1 Patch Availability for Oracle Enterprise Manager Cloud Control 12c (12.1.0.x)

Table 31 describes Error Correction information for Oracle Enterprise Manager Cloud Control 12c (12.1.0.x).

Table 31 Error Correction information for Oracle Enterprise Manager Cloud Control 12c (12.1.0.x)

Patch Information

12.1.0.1

Comments

Final Patch

-

 

PSU On-Request Platforms

-

 

Table 32 describes the available patches for Oracle Enterprise Manager Cloud Control 12c (12.1.0.1).

Table 32 Patch Availability for Oracle Enterprise Manager Cloud Control 12c (12.1.0.1)

Product Home

UNIX

Microsoft Windows 32-Bit

Advisory Number

Comments

Base Platform Repository home

See Section 3.2.4, "Oracle Database"

See Section 3.2.4, "Oracle Database"

See Section 3.2.4, "Oracle Database"

 

Base Platform OMS home

Base Platform Agent home

NA

NA

NA

The 12.1.0.1 Enterprise Manager Cloud Control release includes all security vulnerabilities announced in the CPU Advisory

Base Platform Fusion Middleware home

See Section 3.4.13, "Oracle Fusion Middleware"

See Section 3.4.13, "Oracle Fusion Middleware"

See Section 3.4.13, "Oracle Fusion Middleware"

 

Oracle Database Management Plug-in (12.1.0.x) home

See Section 3.3.2, "Patch Availability for Oracle Database Management Plug-in (12.1.0.x)"

See Section 3.3.2, "Patch Availability for Oracle Database Management Plug-in (12.1.0.x)"

See Section 3.3.2, "Patch Availability for Oracle Database Management Plug-in (12.1.0.x)"

 

3.3.2 Patch Availability for Oracle Database Management Plug-in (12.1.0.x)

Table 33 describes Error Correction information for Oracle Database Management Plug-in (12.1.0.x).

Table 33 Error Correction information for Oracle Database Management Plug-in (12.1.0.x)

Patch Information

12.1.0.2

12.1.0.1

Comments

Final Patch

-

January 2013

 

PSU On-Request Platforms

-

-

 

Table 34 describes the available patches for Oracle Database Management Plug-in (12.1.0.x).

Table 34 Patch Set Update Availability for Oracle Database Management Plug-in (12.1.0.x)

Product Home

UNIX

Microsoft Windows 32-Bit

Advisory Number

Comments

Oracle Database Management Plug-in (12.1.0.2) Home

OR

OR

Released July 2012

 

Oracle Database Management Plug-in (12.1.0.1) Home

OR

OR

Released July 2012

 

3.3.3 Patch Availability for Oracle Enterprise Manager Grid Control 11g (11.1.0.1)

Table 35 describes Error Correction information for Oracle Enterprise Manager Grid Control 11g (11.1.0.1).

Table 35 Error Correction information for Oracle Enterprise Manager Grid Control 11g (11.1.0.1)

Patch Information

11.1.0.1

Comments

Final Patch

April 2018

 

PSU On-Request Platforms

-

 

Table 36 describes the available patches for Oracle Enterprise Manager Grid Control 11g (11.1.0.1).

Table 36 Patch Set Update Availability for Oracle Enterprise Manager Grid Control 11g (11.1.0.1)

Product Home

Patch

Advisory Number

Comments

Base Platform Repository Home

See Section 3.2.4, "Oracle Database"

See Section 3.2.4, "Oracle Database"

 

Base Platform OMS Home

PSU 11.1.0.1.7 Patch 13711705

Released July 2012

 

Base Platform Fusion Middleware home

SPU Patch 14681307

SPU Patch 14364893

CPU Patch 12875001

CPU Patch 12875006

CPU Patch 12874981

CPU Patch 13583186

CPU Patch 10625676

CPU Patch 13442902

CVE-2012-3137

CVE-2011-1411

Released October 2011

Released October 2011

Released October 2011

Released April 2012

Released January 2011

Released January 2012

WLS 10.3.2.0 JDBC Patch (Not a Smart Update patch). Before installing this SPU, see Note 1493990.1, Patching for CVE-2012-3137

WLS 10.3.2.0 CSS patch (Smart Update Patch IDs: A6AX)

WLS 10.3.2.0 JMS patch (Smart Update Patch IDs: 9ZW7)

WLS 10.3.2.0 WebServices patch (Smart Update Patch IDs: L8DT)

WLS 10.3.2.0 Security patch (Smart Update Patch IDs: VHAC, R4P6)

WLS 10.3.2.0 WebApp patch (Smart Update Patch IDs: AYDB, 8IWX)

WLS 10.3.2.0 Core patch (Smart Update Patch IDs: H3QP, Y3IR)

WLS 10.3.2.0 Console patch (Smart Update Patch IDs: 1MVX, PAIS)

Base Platform Repository Home

CPU Patch 13705493

Released April 2012

OC4J 10.1.2.3 one-off patch

Enterprise Manager Grid Control

Base Platform Agent Home

PSU 11.1.0.1.7 Patch 9346282

Released April 2012

 

3.3.4 Patch Availability for Oracle Enterprise Manager Grid Control 10g (10.2.0.5)

Table 37 describes Error Correction information for Oracle Enterprise Manager Grid Control 10g (10.2.0.5).

Table 37 Error Correction information for Oracle Enterprise Manager Grid Control 10g (10.2.0.5)

Patch Information

10.2.0.5

Comments

Final Patch

October 2014

 

PSU On-Request Platforms

-

 

Table 38 describes the available patches for Oracle Enterprise Manager Grid Control 10g (10.2.0.5).

Table 38 Patch Availability for Oracle Enterprise Manager Grid Control 10g (10.2.0.5)

Product Home

Patch

Advisory Number

Comments

Base Platform Repository Home

See Section 3.2.4, "Oracle Database"

See Section 3.2.4, "Oracle Database"

 

Base Platform OMS Home

PSU 10.2.0.5.6 Patch 13701923

Released July 2012

 

Base Platform OMS Home

CPU Patch 14109229

Released January 2012

OC4J 10.1.2.3 one-off patch

Base Platform OMS Home

Unix: CPU Patch 12837860

Microsoft Windows 32-bit: CPU Patch 12837864

Microsoft Windows Itanium 64-bit: CPU Patch 12837867

Released October 2011

See Note 1301699.1, How the SSL/TLS Renegotiation Protocol Change Affects Oracle HTTP Server

Base Platform OMS Home

CPU Patch 12535904

Released July 2011

Applicable to HP-UX PA-RISC and HP-UX Itanium platforms only

Base Platform Agent Home

UNIX: PSU 10.2.0.5.3 Patch 9282414

Windows: PSU 10.2.0.5.3 Patch 9490898

Released April 2010

 

3.3.5 Oracle Real User Experience Insight

Table 39 describes Error Correction information for Oracle Real User Experience Insight 6.0.x.

Table 39 Error Correction information for Oracle Real User Experience Insight

Patch Information

6.0.x

Comments

Final Patch

October 2013

 

CPU On-Request platforms

 

 

Table 40 describes the available patches for Oracle Real User Experience Insight.

Table 40 Patch Availability for Oracle Real User Experience Insight

Product Version

Patch

Advisory Number

Comments

6.0.x

CPU Patch 9268989

Released January 2011

 

3.4 Oracle Fusion Middleware

This section contains the following:

·         Section 3.4.1, "Oracle AquaLogic Data Services Platform"

·         Section 3.4.2, "Oracle AquaLogic Interaction Logging Utilities"

·         Section 3.4.3, "Oracle Beehive"

·         Section 3.4.4, "Oracle Business Intelligence Enterprise Edition"

·         Section 3.4.5, "Oracle Business Intelligence Publisher"

·         Section 3.4.6, "Oracle Business Process Management"

·         Section 3.4.7, "Oracle Communications Converged Application Server"

·         Section 3.4.8, "Oracle Complex Event Processing and WebLogic Event Server"

·         Section 3.4.9, "Oracle Data Service Integrator"

·         Section 3.4.10, "Oracle Document Capture"

·         Section 3.4.11, "Oracle Enterprise Repository"

·         Section 3.4.12, "Oracle Exalogic Patch Set Update (PSU)"

·         Section 3.4.13, "Oracle Fusion Middleware"

·         Section 3.4.14, "Oracle GoldenGate Veridata"

·         Section 3.4.15, "Oracle Hyperion BI+"

·         Section 3.4.16, "Oracle Identity Access Management"

·         Section 3.4.17, "Oracle Identity Management"

·         Section 3.4.18, "Oracle Identity Management Connector"

·         Section 3.4.19, "Oracle Identity Manager"

·         Section 3.4.20, "Oracle Imaging and Process Management"

·         Section 3.4.21, "Oracle JDeveloper"

·         Section 3.4.22, "Oracle JRockit"

·         Section 3.4.23, "Oracle Map Viewer"

·         Section 3.4.24, "Oracle Outside In Technology"

·         Section 3.4.25, "Oracle Portal, Forms, Reports, and Discoverer 11g Release 1"

·         Section 3.4.26, "Oracle Forms and Reports 11g Release 2"

·         Section 3.4.27, "Oracle SOA Suite"

·         Section 3.4.28, "Oracle Single Sign-On/Delegated Administration Services"

·         Section 3.4.29, "Oracle Web-Tier 11g Utilities"

·         Section 3.4.30, "Oracle WebCenter"

·         Section 3.4.31, "Oracle WebCenter Content (Formerly Oracle Universal Content Management)"

·         Section 3.4.32, "Oracle WebCenter Forms Recognition"

·         Section 3.4.33, "Oracle WebCenter Interaction"

·         Section 3.4.34, "Oracle WebCenter Sites (Formerly FatWire Content Server)"

·         Section 3.4.35, "Oracle WebCenter Suite"

·         Section 3.4.36, "Oracle WebLogic Integration"

·         Section 3.4.37, "Oracle WebLogic Portal"

·         Section 3.4.38, "Oracle WebLogic Server and WebLogic Express"

·         Section 3.4.39, "Oracle WebLogic Server"

·         Section 3.4.40, "Oracle WebLogic Server Plug-ins"

·         Section 3.4.41, "Oracle WebLogic SIP Server"

·         Section 3.4.42, "Oracle Workshop for WebLogic"

3.4.1 Oracle AquaLogic Data Services Platform

Table 41 describes the Error Correction information for Oracle AquaLogic Data Services Platform.

Table 41 Error Correction information for Oracle AquaLogic Data Services Platform

Patch Information

ALDSP 3.2

ALDSP 3.0.1

Comments

Final Patch

April 2016

April 2016

 

Table 42 describes the available patches for Oracle AquaLogic Data Services Platform. See also the underlying product stack tables (JRockit and WLS) for any applicable patches.

Table 42 Patch Availability for Oracle AquaLogic Data Services Platform

Product Home

Patch

Advisory Number

Smart Update Patch Set ID

Smart Update Patch IDs

Comments

3.0.1.0

CPU Patch 13705113

Released April 2012

NA

NA

WebLogic Server 9.2.2.0 one-off patch that needs to be applied to WebLogic Server home

3.2

CPU Patch 8272933

Released April 2009

NA

TXJJ

 

3.0.1

CPU Patch 8284035

Released April 2009

NA

QDWJ

 

3.4.2 Oracle AquaLogic Interaction Logging Utilities

Table 43 describes the Error Correction information for Oracle AquaLogic Interaction Logging Utilities.

Table 43 Error Correction information for Oracle AquaLogic Interaction Logging Utilities

Patch Information

6.0

1.0

Comments

Final Patch

October 2012

October 2012

 

Table 44 describes the available patches for Oracle AquaLogic Interaction Logging Utilities. See also the underlying product stack tables for any applicable patches. Refer to comments section and apply the patch to the respective product home.

Table 44 Patch Availability for Oracle AquaLogic Interaction Logging Utilities

Oracle AquaLogic Interaction Logging Utilities

Patch

Advisory Number

Comments

1.0

CPU Patch 13718641

Released April 2012

WebLogic Server 9.2.0.0 one-off patch that needs to be applied to WebLogic Server home

3.4.3 Oracle Beehive

Oracle Beehive environments contain Oracle Database and Oracle Fusion Middleware homes. For more information, see My Oracle Support Note 758816.1, Applying Critical Patch Updates to Beehive 1.5.1.x though 2.0.1.x.

Table 45 describes Error Correction information for Oracle Beehive.

Table 45 Error Correction information for Oracle Beehive

Patch Information

Oracle Beehive 2.0.1.x

Comments

Minimum Product Requirement

2.0.1.4

Announced January 2011

Final Patch

Jan 2018

 

CPU On-Request Platforms

-

 

Table 46 describes the available patches for Oracle Beehive.

For each home you are about to administer, find the appropriate patches based on the components installed in that home. Then, apply those patches in the order listed.

Table 46 Patch Availability for Oracle Beehive

Product Home

UNIX

Microsoft Windows (32-Bit)

Advisory Number

Comments

Oracle Database home

See Section 3.2.4, "Oracle Database"

See Section 3.2.4, "Oracle Database"

See Section 3.2.4, "Oracle Database"

 

Oracle Beehive Server 2.0.1.x

CPU Patch 9173038

CPU Patch 9173038

Released January 2010

 

Oracle Beekeeper 2.0.1.x

NA

NA

 

 

3.4.4 Oracle Business Intelligence Enterprise Edition

Table 47 describes the Error Correction information for Oracle Business Intelligence Enterprise Edition.

Table 47 Error Correction information for Oracle Business Intelligence Enterprise Edition

Patch Information

11.1.1.6.2

11.1.1.6.0

11.1.1.5.0

10.1.3.4.2

Comments

Final Patch

-

-

January 2013

-

 

Table 48 describes the available patches for Oracle Business Intelligence Enterprise Edition.

Customers on earlier versions of Oracle Business Intelligence Enterprise Edition 10.x will need to apply 10.1.3.4.1 and then apply the patch.

Table 48 Patch Availability for Oracle Business Intelligence Enterprise Edition

Product Home

Patch

Advisory Number

Comments

11.1.1.6.2

BP Patch 14630670

CVE-2012-3193, CVE-2012-3194

BIP patch

11.1.1.6.0

BP Patch 14630670

CVE-2012-3193, CVE-2012-3194

BIP patch

11.1.1.5.0

BP Patch 14691557

CVE-2012-3193, CVE-2012-3194

BIP patch

10.1.3.4.2

BP Patch 14625193

CVE-2012-3194

BIP patch

11.1.1.5.0

BP Patch 12830486

Released October 2011

OBIEE Patch

3.4.5 Oracle Business Intelligence Publisher

Table 49 describes the Error Correction information for Oracle Business Intelligence Publisher.

Table 49 Error Correction information for Oracle Business Intelligence Publisher

Patch Information

11.1.1.6.2

11.1.1.6.0

11.1.1.5.0

10.1.3.4.2

Comments

Final Patch

-

-

January 2013

-

 

Table 50 describes the available patches for Oracle Business Intelligence Publisher.

Customers on earlier versions of Oracle Business Intelligence Publisher 10.x will need to apply 10.1.3.4.1 and then apply the patch.

Table 50 Patch Availability for Oracle Business Intelligence Publisher

Product Home

Patch

Advisory Number

Comments

11.1.1.6.2

BP Patch 14630670

CVE-2012-3193, CVE-2012-3194

BIP patch

11.1.1.6.0

BP Patch 14630670

CVE-2012-3193, CVE-2012-3194

BIP patch

11.1.1.5.0

BP Patch 14691557

CVE-2012-3193, CVE-2012-3194

BIP patch

10.1.3.4.2

BP Patch 14625193

CVE-2012-3194

See My Oracle Support Note 797057.1, Overview of Available Update Patches for Oracle BI Publisher Enterprise 10g

3.4.6 Oracle Business Process Management

Follow the special instructions below to download Oracle Business Process Management patches.

1.  Click Patches & Updates after logging into My Oracle Support.

2.  Search for Oracle Business Process Management Suite.

3.  Search for the required BPM release by clicking Select up to 10.

4.  Select the patch with the build number that is indicated in Table 52, or the patch with higher build number than what is indicated for the platform you are about to update, for example: EnterpriseJ2EE, Studio, or EnterpriseSA.

5.  Download the patch.

Table 51 describes the Error Correction information for Oracle Business Process Management.

Table 51 Error Correction information for Oracle Business Process Management

Patch Information

10.3.2

10.3.1

6.0.5

Comments

Final Patch

-

-

July 2014

 

Table 52 describes the available patches for Oracle Business Process Management.

Table 52 Patch Availability for Oracle Business Process Management

Product Home

Patch

Advisory Number

Comments

BPM 10.3.2

100375

Released July 2010

See the instructions above on how to download the patch

BPM 10.3.1

100258

Released July 2010

See the instructions above on how to download the patch

BPM 6.0.5

100247

Released July 2010

See the instructions above on how to download the patch

3.4.7 Oracle Communications Converged Application Server

Table 53 describes the available patches for Oracle Communications Converged Application Server. See also the underlying product stack tables for any applicable patches. Refer to comments section and apply the patch to the respective product home.

Table 53 Patch Availability for Oracle Communications Application Server

Oracle Communications Converged Application Server

Patch

Advisory Number

Comments

5.0

CPU Patch 12875001

CPU Patch 12875006

CPU Patch 12874981

CPU Patch 13705098

CPU Patch 10625676

CPU Patch 13442902

Released October 2011

Released October 2011

Released October 2011

Released April 2012

Released January 2011

Released January 2012

WLS 10.3.3.0 JMS patch

WLS 10.3.3.0 WebServices patch

WLS 10.3.3.0 Security patch

WLS 10.3.3.0 WebApp patch

WLS 10.3.3.0 Core patch

WLS 10.3.3.0 Console patch

4.0

CPU Patch 12875001

CPU Patch 12875006

CPU Patch 12874981

CPU Patch 13705098

CPU Patch 10625676

CPU Patch 13442902

Released October 2011

Released October 2011

Released October 2011

Released April 2012

Released January 2011

Released January 2012

WLS 10.3.0.0 JMS patch

WLS 10.3.0.0 WebServices patch

WLS 10.3.0.0 Security patch

WLS 10.3.0.0 WebApp patch

WLS 10.3.0.0 Core patch

WLS 10.3.0.0 Console patch

3.4.8 Oracle Complex Event Processing and WebLogic Event Server

Table 54 describes the Error Correction information for Oracle Complex Event Processing and WebLogic Event Server.

Table 54 Error Correction information for Oracle Complex Event Processing and WebLogic Event Server

Patch Information

CEP 11.1.6

CEP 11.1.4

EVS 2.0

Comments

Final Patch

-

January 2013

July 2014

 

Table 55 describes the available patches for Oracle Complex Event Processing and WebLogic Event Server. See also the underlying product stack tables (JRockit and WLS) for any applicable patches.

Table 55 Patch Availability for Oracle Complex Event Processing and WebLogic Event Server

Product Home

Patch

Advisory Number

Comments

11.1.1.6

SPU Patch 14356616

CVE-2011-1411

 

11.1.1.4

SPU Patch 14356619

CVE-2011-1411

 

EVS 2.0

Upgrade to 11.1.1.x version, then apply the patch for that version

CVE-2011-1411

 

3.4.9 Oracle Data Service Integrator

Table 56 describes the Error Correction information for Oracle Data Service Integrator.

Table 56 Error Correction information for Oracle Data Service Integrator

Patch Information

ODSI 10.3.0

Comments

Final Patch

January 2017

 

Table 57 describes the available patches for Data Service Integrator. See also the underlying product stack tables (JRockit and WLS) for any applicable patches.

Table 57 Patch Availability for Oracle Data Service Integrator

Product Home

Patch

Advisory Number

Smart Update Patch Set ID

Smart Update Patch IDs

Comments

10.3.0

SPU Patch 14364893

CPU Patch 12875001

CPU Patch 12875006

CPU Patch 12874981

CPU Patch 13583186

CPU Patch 10625676

CPU Patch 13442902

CVE-2011-1411

Released October 2011

Released October 2011

Released October 2011

Released April 2012

Released January 2011

Released January 2012

NA

NA

EXP8

ZVC4

AEQE

QHPL

WT6W

HEYE

RPQH

3QHE, NXQM, 982N, 6BME, 5EGH

EDAT, QR92

VXVR, WSNI, SU7Z, PQVV, ZE59, XW21, VV75

2QSG, E65J

8WHJ, K4VY

WLS 10.3.0.0 CSS patch

WLS 10.3.0.0 JMS patch

WLS 10.3.0.0 WebServices patch

WLS 10.3.0.0 Security patch

WLS 10.3.0.0 WebApp patch

WLS 10.3.0.0 Core patch

WLS 10.3.0.0 Console patch

10.3.0

CPU Patch 8268258

Released April 2009

NA

8XCC

 

3.4.10 Oracle Document Capture

Table 58 describes the Error Correction information for Oracle Document Capture.

Table 58 Error Correction information for Oracle Document Capture

Patch Information

10.1.3.5

10.1.3.4

Comments

Final Patch

-

-

 

Table 59 describes the available patches for Oracle Document Capture.

Table 59 Patch Availability for Oracle Document Capture

Product Home

Patch

Advisory Number

Comments

Oracle Document Capture 10.1.3.5 home

CPU Patch 10350692

Released January 2011

 

Oracle Document Capture 10.1.3.4 home

CPU Patch 10350692

Released January 2011

 

3.4.11 Oracle Enterprise Repository

Table 60 describes the Error Correction information for Oracle Enterprise Repository.

Table 60 Error Correction information for Oracle Enterprise Repository

Patch Information

2.6

Comments

Final Patch

July 2013

 

Table 61 describes the available patches for Oracle Enterprise Repository. See also the underlying product stack tables for any applicable patches. Refer to comments section and apply the patch to the respective product home.

Table 61 Patch Availability for Oracle Enterprise Repository

Product Home

Patch

Advisory Number

Comments

2.6

CPU Patch 13705382

Released April 2012

WebLogic Server 9.2.0.0 one-off patch that needs to be applied to WebLogic Server home

3.4.12 Oracle Exalogic Patch Set Update (PSU)

Table 62 describes the Error Correction information for Exalogic Patch Set Update (PSU).

Table 62 Error Correction information for Oracle Exalogic Patch Set Update (PSU)

Patch Information

2.x

1.x

Comments

Final Patch

-

-

 

Table 63 describes the available patches for Oracle Exalogic.

Table 63 Patch Set Update Availability for Oracle Exalogic

Oracle Exalogic

Patch

Advisory Number

Comments

2.x Physical

PSU Patch 14356592

Exalogic Infrastructure 2.0.0.0.3: Released October 2012

JRockit 28.2.5: CVE-2012-3202

Coherence 3.7.1.6: Released October 2012

WebLogic Server 10.3.6.0.2: CVE-2011-1411

See Note 1314535.1, Announcing Exalogic PSUs (Patch Set Updates)

Oracle Exalogic 2.x PSU is available only for Linux x86-64 platforms for Exalogic X2-2 systems running EECS 2.0 in a physical (NOT virtual) configuration

1.x

PSU Patch 14356583

Exalogic Infrastructure 1.0.0.2.6: Released October 2012

Java SE 6u37: Java Advisory

Coherence 3.7.1.6: Released October 2012

WebLogic Server 10.3.4.0.5: Released April 2012

See Note 1314535.1, Announcing Exalogic PSUs (Patch Set Updates)

Oracle Exalogic 1.x PSU is available only for Oracle Solaris x86-64 platforms

3.4.13 Oracle Fusion Middleware

Additional information may be found in My Oracle Support Note 405972.1, Oracle Application Server 10g Examples for Critical Patch Updates.

This section contains the following:

·         Section 3.4.13.1, "Patch Availability for Oracle Fusion Middleware 11.1.2.0"

·         Section 3.4.13.2, "Patch Availability for Oracle Fusion Middleware 11.1.1.6"

·         Section 3.4.13.3, "Patch Availability for Oracle Fusion Middleware 11.1.1.5"

·         Section 3.4.13.4, "Patch Availability for Oracle Fusion Middleware 11.1.1.4 Portal, Forms, Reports and Discoverer"

·         Section 3.4.13.5, "Patch Availability for Oracle Fusion Middleware 10.1.3.5.x"

3.4.13.1 Patch Availability for Oracle Fusion Middleware 11.1.2.0

Table 64 describes the Error Correction information for Oracle Fusion Middleware 11.1.2.0.

Table 64 Error Correction information for Oracle Forms and Reports 11g Release 2

Patch Information

11.1.2.0

Comments

Final Patch

-

 

CPU On-Request Platforms

-

 

Table 65 describes the available patches for Oracle Fusion Middleware 11.1.2.0.

Table 65 Patch Availability for Oracle Forms and Reports 11g Release 2

Product Home

Patches

Advisory Number

Comments

Oracle Database home

See Section 3.2.4, "Oracle Database"

See Section 3.2.4, "Oracle Database"

 

Oracle Java SE home

See Oracle Java SE Critical Patch Update

See Oracle Java SE Critical Patch Update

See Note 1492980.1, How to Maintain the Java SE Installed or Used with FMW 11g Products

Oracle JRockit 28.x home

See Section 3.4.22, "Oracle JRockit"

See Section 3.4.22, "Oracle JRockit"

 

Oracle WebLogic Server home

See Section 3.4.39, "Oracle WebLogic Server"

See Section 3.4.39, "Oracle WebLogic Server"

See Note 1306505.1, Announcing Oracle WebLogic Server PSUs (Patch Set Updates)

Oracle WebLogic Server Plug-ins

See Section 3.4.40, "Oracle WebLogic Server Plug-ins"

See Section 3.4.40, "Oracle WebLogic Server Plug-ins"

See Note 1111903.1, WebLogic Server 10gR3 (10.3.0) and 11gR1 (10.3.x) - Web Server Plug-In Support

Oracle Forms and Reports 11.1.2.0 home

See Section 3.2.4.4, "Oracle Database 11.1.0.7"

See Section 3.2.4.4, "Oracle Database 11.1.0.7"

Before patching an Oracle Database Server, you might need to patch the Database 11.1.0.7 client in the Fusion Middleware home. Before installing the applicable patches, see Note 1493990.1Patching for CVE-2012-3137

Oracle Forms and Reports 11.1.2.0 home

SPU Patch 14669281

CVE-2012-3137

Oracle JDBC Patch

Before installing this SPU, see Note 1493990.1, Patching for CVE-2012-3137

Oracle Forms and Reports 11.1.2.0 home

SPU Patch 14373992

CVE-2012-3152, CVE-2012-3153

Oracle Reports Developer patch

After patch installation or upgrade, see Note 1480206.1, REP-52262: Diagnostic Output is Disabled, and Note 1479064.1, New Feature: <urlEngineAccess> Controls URLEngine (rwURL) Sources

Oracle Forms and Reports 11.1.2.0 home

CPU Patch 14003475

Released July 2012

Oracle HTTP Server patch

Oracle Forms and Reports 11.1.2.0 home

CPU Patch 13113602

Released January 2012

Oracle Web Services Manager patch

Oracle Forms and Reports 11.1.2.0 home

CPU Patch 12434187

Released July 2011

Network

3.4.13.2 Patch Availability for Oracle Fusion Middleware 11.1.1.6

Table 66 describes the Error Correction information for Oracle Fusion Middleware 11.1.1.6.

Table 66 Error Correction information for Oracle Fusion Middleware 11.1.1.6

Patch Information

11.1.1.6

Comments

Final Patch

-

 

CPU On-Request Platforms

-

 

Table 67 describes the available patches for Oracle Fusion Middleware 11.1.1.6.

Table 67 Patch Availability for Oracle Fusion Middleware 11.1.1.6

Product Home

Patches

Advisory Number

Comments

Oracle Database home

See Section 3.2.4, "Oracle Database"

See Section 3.2.4, "Oracle Database"

 

Oracle Java SE home

See Oracle Java SE Critical Patch Update

See Oracle Java SE Critical Patch Update

See Note 1492980.1, How to Maintain the Java SE Installed or Used with FMW 11g Products

Oracle JRockit 28.x home

See Section 3.4.22, "Oracle JRockit"

See Section 3.4.22, "Oracle JRockit"

 

Oracle WebLogic Server home

See Section 3.4.39, "Oracle WebLogic Server"

See Section 3.4.39, "Oracle WebLogic Server"

See Note 1306505.1, Announcing Oracle WebLogic Server PSUs (Patch Set Updates)

Oracle WebLogic Server Plug-ins

See Section 3.4.40, "Oracle WebLogic Server Plug-ins"

See Section 3.4.40, "Oracle WebLogic Server Plug-ins"

See Note 1111903.1, WebLogic Server 10gR3 (10.3.0) and 11gR1 (10.3.x) - Web Server Plug-In Support

Oracle Identity Management 11.1.1.6.0 home

Oracle Identity Access Management 11.1.1.6.0 home

Oracle Web Tier 11.1.1.6.0 home

Oracle Portal, Forms, Reports and Discoverer 11.1.1.6.0 home

See Section 3.2.4.4, "Oracle Database 11.1.0.7"

See Section 3.2.4.4, "Oracle Database 11.1.0.7"

Before patching an Oracle Database Server, you might need to patch the Database 11.1.0.7 client in the Fusion Middleware home. Before installing the applicable patches, see Note 1493990.1Patching for CVE-2012-3137

Oracle Portal, Forms, Reports and Discoverer 11.1.1.6.0 home

SPU Patch 14373988

CVE-2012-3152, CVE-2012-3153

Oracle Reports Developer patch

After patch installation or upgrade, see Note 1480206.1, REP-52262: Diagnostic Output is Disabled, and Note 1479064.1, New Feature: <urlEngineAccess> Controls URLEngine (rwURL) Sources

Oracle Single Sign-On / Delegated Administration Services home

SPU Patch 14491148

CVE-2012-3175, CVE-2012-0518

Oracle Fusion Middleware Single Sign-On patch

Oracle Identity Management 11.1.1.6.0 home

Oracle Web Tier 11.1.1.6.0 home

Oracle Portal, Forms, Reports and Discoverer 11.1.1.6.0 home

CPU Patch 14003476

Released July 2012

Oracle HTTP Server patch

Oracle WebCenter Content 11.1.1.6 home

CPU Patch 13586432

Released January 2012

 

Oracle Single Sign-On / Delegated Administration Services home

CPU Patch 13826368

Released January 2012

OC4J Patch

Oracle Single Sign-On / Delegated Administration Services home

Unix: CPU Patch 12837860

Microsoft Windows 32-bit: CPU Patch 12837864

Microsoft Windows Itanium 64-bit: CPU Patch 12837867

Released October 2011

See Note 1301699.1, How the SSL/TLS Renegotiation Protocol Change Affects Oracle HTTP Server

3.4.13.3 Patch Availability for Oracle Fusion Middleware 11.1.1.5

Table 68 describes the Error Correction information for Oracle Fusion Middleware 11.1.1.5.

Table 68 Error Correction information for Oracle Fusion Middleware 11.1.1.5

Patch Information

11.1.1.5

Comments

Final Patch

January 2013

 

CPU On-Request Platforms

-

 

Table 69 describes the available patches for Oracle Fusion Middleware 11.1.1.5.

Table 69 Patch Availability for Oracle Fusion Middleware 11.1.1.5

Product Home

Patches

Advisory Number

Comments

Oracle Database home

See Section 3.2.4, "Oracle Database"

See Section 3.2.4, "Oracle Database"

 

Oracle Java SE home

See Oracle Java SE Critical Patch Update

See Oracle Java SE Critical Patch Update

See Note 1492980.1, How to Maintain the Java SE Installed or Used with FMW 11g Products

Oracle JRockit 28.x home

See Section 3.4.22, "Oracle JRockit"

See Section 3.4.22, "Oracle JRockit"

 

Oracle WebLogic Server home

See Section 3.4.39, "Oracle WebLogic Server"

See Section 3.4.39, "Oracle WebLogic Server"

See Note 1306505.1, Announcing Oracle WebLogic Server PSUs (Patch Set Updates)

Oracle WebLogic Server Plug-ins

See Section 3.4.40, "Oracle WebLogic Server Plug-ins"

See Section 3.4.40, "Oracle WebLogic Server Plug-ins"

See Note 1111903.1, WebLogic Server 10gR3 (10.3.0) and 11gR1 (10.3.x) - Web Server Plug-In Support

Oracle Identity Access Management installation within Oracle SOA Suite 11.1.1.5 home

See Section 3.4.19, "Oracle Identity Manager"

See Section 3.4.19, "Oracle Identity Manager"

Oracle Identity Manager patch

Oracle Identity Management 11.1.1.5.0 home

Oracle Identity Access Management 11.1.1.5.0 home

Oracle Web Tier 11.1.1.5.0 home

See Section 3.2.4.4, "Oracle Database 11.1.0.7"

See Section 3.2.4.4, "Oracle Database 11.1.0.7"

Before patching an Oracle Database Server, you might need to patch the Database 11.1.0.7 client in the Fusion Middleware home. Before installing the applicable patches, see Note 1493990.1Patching for CVE-2012-3137

Oracle Fusion Middleware 11.1.1.5 home

SPU Patch 14669281

CVE-2012-3137

Oracle JDBC Patch

Before installing this SPU, see Note 1493990.1 Patching for CVE-2012-3137

Oracle Identity Management 11.1.1.5.0 home

Oracle Identity Access Management 11.1.1.5.0 home

Oracle Web Tier 11.1.1.5.0 home

CPU Patch 14003475

Released July 2012

Oracle HTTP Server patch

Oracle Identity Management 11.1.1.5.0 home

Oracle Identity Access Management 11.1.1.5.0 home

Oracle SOA Suite 11.1.1.5.0 home

Oracle WebCenter Suite 11.1.1.5.0 home

Oracle Web Tier 11.1.1.5.0 home

CPU Patch 13113602

Released January 2012

Oracle Web Services Manager patch

Oracle Single Sign-On / Delegated Administration Services home

CPU Patch 13826368

Released January 2012

OC4J Patch

Oracle WebCenter Content 11.1.1.5 home

CPU Patch 13502977

Released January 2012

 

Oracle Single Sign-On / Delegated Administration Services home

Unix: CPU Patch 12837860

Microsoft Windows 32-bit: CPU Patch 12837864

Microsoft Windows Itanium 64-bit: CPU Patch 12837867

Released October 2011

See Note 1301699.1, How the SSL/TLS Renegotiation Protocol Change Affects Oracle HTTP Server

Oracle Identity Management 11.1.1.5.0 home

Oracle Identity Access Management 11.1.1.5.0 home

Oracle Web Tier 11.1.1.5.0 home

CPU Patch 12434187

Released July 2011

Network

For Solaris x86-64, (Identity Management and Web Tier homes), apply specific mandatory patches. For more information, see My Oracle Support Note 1343107.1

3.4.13.4 Patch Availability for Oracle Fusion Middleware 11.1.1.4 Portal, Forms, Reports and Discoverer

Oracle Fusion Middleware 11.1.1.4 is out of error correction for all products except Portal, Forms, Reports and Discoverer.

Oracle Fusion Middleware 10.1.4.3 is also out of error correction except Oracle Single Sign-On/Delegated Administration Services 10.1.4.3 when it is used in Portal, Forms, Reports and Discoverer 11.1.x.

For more information, see My Oracle Support Note 209768.1, Database, FMW, EM Grid Control, and OCS Software Error Correction Support Policy.

Table 75 describes the Error Correction information for Oracle Middleware 11.1.1.4 Portal, Forms, Reports and Discoverer.

Table 70 Error Correction information for Oracle Middleware 11.1.1.4 Portal, Forms, Reports and Discoverer

Patch Information

Portal, Forms, Reports and Discoverer 11.1.1.4

Comments

Final Patch

January 2013

For more information, see Lifetime Support Policy for Oracle Fusion Middleware

Table 71 describes the available patches for Oracle Fusion Middleware 11.1.1.4 Portal, Forms, Reports and Discoverer.

Table 71 Patch Availability for Oracle Fusion Middleware 11.1.1.4 Portal, Forms, Reports and Discoverer

Product Home

Patches

Advisory Number

Comments

Oracle Database home

See Section 3.2.4, "Oracle Database"

See Section 3.2.4, "Oracle Database"

 

Oracle Java SE home

See Oracle Java SE Critical Patch Update

See Oracle Java SE Critical Patch Update

See Note 1492980.1, How to Maintain the Java SE Installed or Used with FMW 11g Products

Oracle JRockit 28.x home

See Section 3.4.22, "Oracle JRockit"

See Section 3.4.22, "Oracle JRockit"

 

Oracle WebLogic Server Plug-ins

See Section 3.4.40, "Oracle WebLogic Server Plug-ins"

See Section 3.4.40, "Oracle WebLogic Server Plug-ins"

See Note 1111903.1, WebLogic Server 10gR3 (10.3.0) and 11gR1 (10.3.x) - Web Server Plug-In Support

Oracle Identity Management 11.1.1.4.0 home

Oracle Identity Access Management 11.1.1.4.0 home

Oracle Web Tier 11.1.1.4.0 home

Oracle Portal, Forms, Reports and Discoverer 11.1.1.4.0 home

See Section 3.2.4.4, "Oracle Database 11.1.0.7"

See Section 3.2.4.4, "Oracle Database 11.1.0.7"

Before patching an Oracle Database Server, you might need to patch the Database 11.1.0.7 client in the Fusion Middleware home. Before installing the applicable patches, see Note 1493990.1Patching for CVE-2012-3137

Oracle Portal, Forms, Reports and Discoverer 11.1.1.4.0 home

SPU Patch 14373984

CVE-2012-3152, CVE-2012-3153

Oracle Reports Developer patch

After patch installation or upgrade, see Note 1480206.1, REP-52262: Diagnostic Output is Disabled , and Note 1479064.1, New Feature: <urlEngineAccess> Controls URLEngine (rwURL) Sources

Oracle Single Sign-On / Delegated Administration Services home

SPU Patch 14491148

CVE-2012-3175, CVE-2012-0518

Oracle Fusion Middleware Single Sign-On patch

Oracle WebLogic Server home

PSU Patch 13568073

Released April 2012

See Note 1306505.1, Announcing Oracle WebLogic Server PSUs (Patch Set Updates)

Oracle Identity Management 11.1.1.4.0 home

Oracle Portal, Forms, Reports and Discoverer 11.1.1.4.0 home

CPU Patch 13113594

Released January 2012

Oracle Web Services Manager patch

Oracle Single Sign-On / Delegated Administration Services home

CPU Patch 13826368

Released January 2012

OC4J Patch

Oracle Identity Management 11.1.1.4.0 home

Oracle Portal, Forms, Reports and Discoverer 11.1.1.4.0 home

CPU Patch 12959536

Released October 2011

Oracle HTTP Server patch

Oracle Single Sign-On / Delegated Administration Services home

Unix: CPU Patch 12837860

Microsoft Windows 32-bit: CPU Patch 12837864

Microsoft Windows Itanium 64-bit: CPU Patch 12837867

Released October 2011

See Note 1301699.1, How the SSL/TLS Renegotiation Protocol Change Affects Oracle HTTP Server

Oracle Identity Management 11.1.1.4.0 home

Oracle Portal, Forms, Reports and Discoverer 11.1.1.4.0 home

CPU Patch 12434184

Released July 2011

Network

For Solaris x86-64, (Identity Management and Web Tier homes), apply specific mandatory patches. For more information, see My Oracle Support Note 1343107.1

3.4.13.5 Patch Availability for Oracle Fusion Middleware 10.1.3.5.x

Table 72 describes the Error Correction information for Oracle Fusion Middleware 10.1.3.5.x.

Table 72 Error Correction information for Oracle Fusion Middleware 10.1.3.5.x

Patch Information

10.1.3.5.x

Comments

Final Patch

Oracle SOA Suite: October 2014

Other 10.1.3.5.x components: April 2017

For more information, see Lifetime Support Policy for Oracle Fusion Middleware

CPU On-Request Platforms

Oracle Solaris x86-64

 

Table 73 describes the available patches for Oracle Fusion Middleware 10.1.3.5.x.

For information about the different types of installations, see My Oracle Support Note 405972.1, Oracle Application Server 10g Examples for Critical Patch Updates.

Table 73 Patch Availability for Oracle Fusion Middleware 10.1.3.5.x

Product Home

Patches

Advisory Number

Comments

Oracle Database home

See Section 3.2.4, "Oracle Database"

See Section 3.2.4, "Oracle Database"

 

Oracle Application Server 10g Release 3

Oracle HTTP Server 2.0 standalone home

Oracle SOA Suite 10g

Oracle WebCenter Suite 10g

Oracle SOA Suite 10g for WebLogic Server

UNIX: CPU Patch 14010540

Microsoft Windows (32-Bit): CPU Patch 14010541

Microsoft Windows Itanium (64-Bit): CPU Patch 14010543

Released July 2012

See Note 1301699.1, How the SSL/TLS Renegotiation Protocol Change Affects Oracle HTTP Server

OC4J Standalone home

CPU Patch 14123312

Released July 2012

Enterprise Manager AS Control patch

Patch for OC4J Standalone 10.1.3.5 media available on OTN http://www.oracle.com/technetwork/middleware/ias/downloads/utilsoft-090603.html

OC4J Standalone home

CPU Patch 13564288

Released April 2012

Patch for OC4J Standalone 10.1.3.5 media available on OTN http://www.oracle.com/technetwork/middleware/ias/downloads/utilsoft-090603.html

Oracle SOA Suite 10g for WebLogic Server

CPU Patch 12539587

Released October 2011

Oracle Web Services Manager (OWSM) patch

Oracle SOA Suite 10g

Oracle WebCenter Suite 10g

CPU Patch 12957596

Released October 2011

Oracle Web Services Manager (OWSM) patch

3.4.14 Oracle GoldenGate Veridata

Table 74 describes the minimum product requirements for Oracle GoldenGate Veridata. The CPU security vulnerabilities are fixed in the listed release and later releases. The Oracle GoldenGate Veridata downloads and installation instructions can be found at http://www.oracle.com/technetwork/middleware/goldengate/overview/index.html.

Table 74 Minimum Product Requirements for Oracle GoldenGate Veridata

Component

Release

Advisory Number

Comments

Oracle GoldenGate Veridata

3.0.0.6

Released January 2011

 

3.4.15 Oracle Hyperion BI+

Table 75 describes the Error Correction information for Oracle Hyperion BI+.

Table 75 Error Correction information for Oracle Hyperion BI+

Patch Information

11.1.1.3

Comments

Final Patch

July 2013

 

Table 76 describes the available patches for Oracle Hyperion BI+, based on release. Customers who need patches for 11.1.1.2 and 11.1.1.1, contact Oracle Support.

Table 76 Patch Availability for Oracle Hyperion BI+

Product Home

Patch

Advisory Number

Comments

11.1.1.3

CPU Patch 11716379

Released July 2012

 

3.4.16 Oracle Identity Access Management

For the appropriate product versions listed below, refer to the corresponding Oracle Fusion Middleware patch availability sections that contain information on Error Correction, and for the patches to apply. Not all homes that are listed in those sections might be present in the Oracle Identity Access Management installation. Only the relevant homes from those tables need to be patched.

Table 78 describes the available patches for Oracle Identity Access Management.

Table 77 Patch Availability information for Oracle Identity Access Management

Product Home

Patches

Comments

Oracle Identity Access Management 11.1.1.5.0 home

See Section Section 3.4.13.3, "Patch Availability for Oracle Fusion Middleware 11.1.1.5"

 

3.4.17 Oracle Identity Management

For the appropriate product versions listed below, refer to the corresponding Oracle Fusion Middleware patch availability sections that contain information on Error Correction, and for the patches to apply. Not all homes that are listed in those sections might be present in the Oracle Identity Management installation. Only the relevant homes from those tables need to be patched.

Table 78 describes the available patches for Oracle Identity Management.

Table 78 Patch Availability information for Oracle Identity Management

Product Home

Patches

Comments

Oracle Identity Management 11.1.1.6.0 home

See Section Section 3.4.13.2, "Patch Availability for Oracle Fusion Middleware 11.1.1.6"

 

Oracle Identity Management 11.1.1.5.0 home

See Section Section 3.4.13.3, "Patch Availability for Oracle Fusion Middleware 11.1.1.5"

 

Oracle Identity Management 11.1.1.4.0 home

See Section Section 3.4.13.4, "Patch Availability for Oracle Fusion Middleware 11.1.1.4 Portal, Forms, Reports and Discoverer"

 

3.4.18 Oracle Identity Management Connector

Table 79 describes the Error Correction information for Oracle Identity Management Connector.

Table 79 Error Correction information for Oracle Identity Management Connector

Patch Information

9.1.0.4

Comments

Final Patch

April 2017

 

Table 80 describes the available patches for Oracle Identity Manager.

Table 80 Patch Availability for Oracle Identity Management Connector

Product Home

Patch

Advisory Number

Comments

9.1.0.4

CPU Patch 13636081

Released April 2012

 

3.4.19 Oracle Identity Manager

Table 81 describes the Error Correction information for Oracle Identity Manager.

Table 81 Error Correction information for Oracle Identity Manager

Patch Information

11.1.1.5

11.1.1.3

9.1.0.2

Comments

Final Patch

January 2013

January 2012

October 2013

 

Table 82 describes the available patches for Oracle Identity Manager.

Table 82 Patch Availability for Oracle Identity Manager

Product Home

Patch

Advisory Number

Comments

11.1.1.5.0

CPU Patch 13399365

Released April 2012

11.1.1.5.0 Bundle patch 2 or any later bundle patch

11.1.1.3.0

CPU Patch 13589894

Released April 2012

11.1.1.3.0 Bundle patch 8 or any later bundle patch

9.1.0.2

CPU Patch 9588374

Released July 2010

Bundle patch 8 or any later bundle patch

3.4.20 Oracle Imaging and Process Management

Table 81 describes the Error Correction information for Oracle Imaging and Process Management.

Table 83 Error Correction information for Oracle Imaging and Process Management

Patch Information

10.1.3.6

Comments

Final Patch

October 2015

 

Table 86 describes the available patches for Oracle Imaging and Process Management.

Table 84 Critical Patch Update Availability for Oracle Imaging and Process Management

Release

Patch

Advisory Number

Comments

10.1.3.6

CPU Patch 14756862

CVE-2012-0071, CVE-2012-0086, CVE-2012-0090, CVE-2012-0092, CVE-2012-0093, CVE-2012-0095, CVE-2012-0106, CVE-2012-0107, CVE-2012-0108

 

3.4.21 Oracle JDeveloper

Table 81 describes the Error Correction information for Oracle JDeveloper.

Table 85 Error Correction information for Oracle JDeveloper

Patch Information

10.1.3.5

Comments

Final Patch

April 2017

 

Table 86 describes the available patches for Oracle JDeveloper.

Table 86 Critical Patch Update Availability for Oracle JDeveloper

Release

Patch

Advisory Number

Comments

10.1.3.5

CPU Patch 13658027

Released April 2012

 

3.4.22 Oracle JRockit

Table 87 describes the Critical Patch Update availability for Oracle JRockit.

Oracle JRockit R28.2.5 and R27.7.4 include fixes for all security advisories that have been released through CPUOct2012.

Table 87 Critical Patch Update Availability for Oracle JRockit

Oracle JRockit

R28.2.5

R27.7.4

Advisory Number

Comments

JRE and JDK 6

Patch 14261101

NA

CVE-2012-3202

See My Oracle Support Note 952078.1 for known issues/patches with regards to WLS SSL

JRE and JDK 5

Patch 14261097

Patch 14261112

CVE-2012-3202

 

3.4.23 Oracle Map Viewer

Table 88 describes the Error Correction information for Oracle Map Viewer.

Table 88 Error Correction information for Oracle Map Viewer

Patch Information

11.1.1.6.0

11.1.1.5.0

10.1.3.1.0

Comments

Final Patch

-

January 2013

-

 

Table 89 describes the available patches for Oracle Map Viewer.

Table 89 Patch Availability for Oracle Map Viewer

Product Home

Patch

Advisory Number

Comments

11.1.1.6.0

CPU Patch 14065245

Released July 2012

 

11.1.1.5.0

CPU Patch 13997309

Released July 2012

 

10.1.3.1.0

CPU Patch 13997316

Released July 2012

 

3.4.24 Oracle Outside In Technology

Table 90 describes the Error Correction information for Oracle Outside In Technology.

Table 90 Error Correction information for Oracle Outside In Technology

Patch Information

8.3.7

Comments

Final Patch

-

 

Table 91 describes the available patches for Oracle Outside in Technology.

Table 91 Patch Availability for Oracle Outside In Technology

Product Home

Patch

Advisory Number

Comments

Oracle Outside In Technology 8.3.7

CPU Patch 14532721

CVE-2012-3214, CVE-2012-3217

 

3.4.25 Oracle Portal, Forms, Reports, and Discoverer 11g Release 1

For the appropriate product versions listed below, refer to the corresponding Oracle Fusion Middleware patch availability sections that contain information on Error Correction, and for the patches to apply. Not all homes that are listed in those sections might be present in the Oracle Portal, Forms, Reports, and Discoverer 11g Release 1 installation. Only the relevant homes from those tables need to be patched.

Table 92 describes the available patches for Oracle Portal, Forms, Reports, and Discoverer 11g Release 1.

Table 92 Patch Availability information for Oracle Portal, Forms, Reports, and Discoverer 11g Release 1

Product Home

Patches

Comments

Oracle Portal, Forms, Reports and Discoverer 11.1.1.6.0 home

See Section Section 3.4.13.2, "Patch Availability for Oracle Fusion Middleware 11.1.1.6"

 

Oracle Portal, Forms, Reports and Discoverer 11.1.1.4.0 home

See Section Section 3.4.13.4, "Patch Availability for Oracle Fusion Middleware 11.1.1.4 Portal, Forms, Reports and Discoverer"

 

3.4.26 Oracle Forms and Reports 11g Release 2

For the appropriate product versions listed below, refer to the corresponding Oracle Fusion Middleware patch availability sections that contain information on Error Correction, and for the patches to apply. Not all homes that are listed in those sections might be present in the Oracle Forms and Reports 11g Release 2 installation. Only the relevant homes from those tables need to be patched.

Table 97 describes the available patches for Oracle Forms and Reports 11g Release 2.

Table 93 Patch Availability information for Oracle Forms and Reports 11g Release 2

Product Home

Patches

Comments

Oracle Forms and Reports 11.1.2.0 home

See Section 3.4.26, "Oracle Forms and Reports 11g Release 2"

 

3.4.27 Oracle SOA Suite

For the appropriate product versions listed below, refer to the corresponding Oracle Fusion Middleware patch availability sections that contain information on Error Correction, and for the patches to apply. Not all homes that are listed in those sections might be present in the Oracle SOA Suite installation. Only the relevant homes from those tables need to be patched.

Table 94 describes the available patches for Oracle SOA Suite.

Table 94 Patch Availability information for Oracle SOA Suite

Product Home

Patches

Comments

Oracle SOA Suite 11.1.1.6.0 home

See Section 3.4.13.2, "Patch Availability for Oracle Fusion Middleware 11.1.1.6"

 

Oracle SOA Suite 11.1.1.5.0 home

See Section 3.4.13.3, "Patch Availability for Oracle Fusion Middleware 11.1.1.5"

 

3.4.28 Oracle Single Sign-On/Delegated Administration Services

For the appropriate product versions listed below, refer to the corresponding Oracle Fusion Middleware patch availability sections that contain information on Error Correction, and for the patches to apply. Not all homes that are listed in those sections might be present in the Oracle Single Sign-On/Delegated Administration Services installation. Only the relevant homes from those tables need to be patched.

Table 95 describes the available patches for Oracle Single Sign-On/Delegated Administration Services.

Table 95 Patch Availability information for Oracle Single Sign-On/Delegated Administration Services

Product Home

Patches

Comments

Oracle Single Sign-On / Delegated Administration Services home

See Section 3.4.13.2, "Patch Availability for Oracle Fusion Middleware 11.1.1.6"

 

Oracle Single Sign-On / Delegated Administration Services home

See Section 3.4.13.4, "Patch Availability for Oracle Fusion Middleware 11.1.1.4 Portal, Forms, Reports and Discoverer"

 

3.4.29 Oracle Web-Tier 11g Utilities

For the appropriate product versions listed below, refer to the corresponding Oracle Fusion Middleware patch availability sections that contain information on Error Correction, and for the patches to apply. Not all homes that are listed in those sections might be present in the Oracle Web-Tier 11g Utilities installation. Only the relevant homes from those tables need to be patched.

Table 96 describes the available patches for Oracle Web-Tier 11g Utilities.

Table 96 Patch Availability information for Oracle Web-Tier 11g Utilities

Product Home

Patches

Comments

Oracle Web-Tier 11g Utilities 11.1.1.6.0 home

See Section 3.4.13.2, "Patch Availability for Oracle Fusion Middleware 11.1.1.6"

 

Oracle Web-Tier 11g Utilities 11.1.1.5.0 home

See Section 3.4.13.3, "Patch Availability for Oracle Fusion Middleware 11.1.1.5"

 

3.4.30 Oracle WebCenter

For the appropriate product versions listed below, refer to the corresponding Oracle Fusion Middleware patch availability sections that contain information on Error Correction, and for the patches to apply. Not all homes that are listed in those sections might be present in the Oracle WebCenter installation. Only the relevant homes from those tables need to be patched.

Table 97 describes the available patches for Oracle WebCenter.

Table 97 Patch Availability information for Oracle WebCenter

Product Home

Patches

Comments

Oracle WebCenter 11.1.1.6.0 home

See Section 3.4.13.2, "Patch Availability for Oracle Fusion Middleware 11.1.1.6"

 

Oracle WebCenter 11.1.1.5.0 home

See Section 3.4.13.3, "Patch Availability for Oracle Fusion Middleware 11.1.1.5"

 

3.4.31 Oracle WebCenter Content (Formerly Oracle Universal Content Management)

Table 98 describes the Error Correction information for Oracle WebCenter Content (formerly Oracle Universal Content Management).

Table 98 Error Correction information for WebCenter Content

Patch Information

10.1.3.5.1

7.5.2

Comments

Final Patch

December 2015

April 2013

 

Table 99 describes the available patches for Oracle WebCenter Content (formerly Oracle Universal Content Management).

Table 99 Patch Availability for Oracle WebCenter Content

Component

Patch

Advisory Number

Comments

Oracle WebCenter Content 11.1.1.6 home

See Section 3.4.13.2, "Patch Availability for Oracle Fusion Middleware 11.1.1.6"

See Section 3.4.13.2, "Patch Availability for Oracle Fusion Middleware 11.1.1.6"

 

Oracle WebCenter Content 11.1.1.5 home

See Section 3.4.13.3, "Patch Availability for Oracle Fusion Middleware 11.1.1.5"

See Section 3.4.13.3, "Patch Availability for Oracle Fusion Middleware 11.1.1.5"

 

Oracle WebCenter Content 10.1.3.5.1 home

CPU Patch 13502938

Released January 2012

 

Oracle WebCenter Content 7.5.2 home

CPU Patch 13526049

Released January 2012

 

3.4.32 Oracle WebCenter Forms Recognition

Table 100 describes the Error Correction information for Oracle WebCenter Forms Recognition.

Table 100 Error Correction information for Oracle WebCenter Forms Recognition

Patch Information

10.1.3.5

Comments

Final Patch

-

 

Table 101 describes the available patches for Oracle WebCenter Forms Recognition. See also the underlying product stack tables for any applicable patches. Refer to comments section and apply the patch to the respective product home.

Table 101 Patch Availability for Oracle WebCenter Forms Recognition

Oracle WebCenter Forms Recognition

Patch

Advisory Number

Comments

10.1.3.5

CPU Patch 13882540

Released April 2012

 

3.4.33 Oracle WebCenter Interaction

Table 102 describes the Error Correction information for Oracle WebCenter Interaction.

Table 102 Error Correction information for Oracle WebCenter Interaction

Patch Information

6.5.1

Comments

Final Patch

October 2012

 

Table 103 describes the available patches for Oracle WebCenter Interaction. See also the underlying product stack tables for any applicable patches. Refer to comments section and apply the patch to the respective product home.

Table 103 Patch Availability for Oracle WebCenter Interaction

Oracle WebCenter Interaction

Patch

Advisory Number

Comments

6.5.1

CPU Patch 13718635

Released April 2012

WebLogic Server 9.2.0.0 one-off patch that needs to be applied to WebLogic Server home

3.4.34 Oracle WebCenter Sites (Formerly FatWire Content Server)

Table 104 describes the Error Correction information for Oracle WebCenter Sites (formerly FatWire Content Server).

Table 104 Error Correction information for Oracle WebCenter Sites (formerly FatWire Content Server)

Patch Information

11.1.1.6.0

7.6.2

7.6.1, 7.5, 7.0.3, 7.0.2, 7.0.1, 7.0, 6.3.x, 6.2, 6.1

Comments

Final Patch

-

-

January 2013

 

Table 105 describes the available patches for Oracle WebCenter Sites. See also the underlying product stack tables.

Table 105 Patch Availability for Oracle WebCenter Sites

Product Home

Patch

Advisory Number

Comments

11.1.1.6.0

CPU Patch 14750912

CVE-2012-3185, CVE-2012-3186, CVE-2012-5065

 

7.6.2

CPU Patch 14583638

CVE-2012-3183, CVE-2012-3185, CVE-2012-3186, CVE-2012-5065

 

7.6.1

CPU Patch 14583579

CVE-2012-3183, CVE-2012-3184, CVE-2012-3185, CVE-2012-3186, CVE-2012-5065

 

7.5

Upgrade to 7.6.1 or later version and apply CPU patch

CVE-2012-3183, CVE-2012-3184, CVE-2012-3185, CVE-2012-3186, CVE-2012-5065

 

7.0.3

Upgrade to 7.6.1 or later version and apply CPU patch

CVE-2012-3183, CVE-2012-3184, CVE-2012-3185, CVE-2012-3186, CVE-2012-5065

 

7.0.2

Upgrade to 7.6.1 or later version and apply CPU patch

CVE-2012-3183, CVE-2012-3184, CVE-2012-3185, CVE-2012-3186, CVE-2012-5065

 

7.0.1

Upgrade to 7.6.1 or later version and apply CPU patch

CVE-2012-3183, CVE-2012-3184, CVE-2012-3185, CVE-2012-3186, CVE-2012-5065

 

7.0

Upgrade to 7.6.1 or later version and apply CPU patch

CVE-2012-3183, CVE-2012-3184, CVE-2012-3185, CVE-2012-3186, CVE-2012-5065

 

6.3.x

Upgrade to 7.6.1 or later version and apply CPU patch

CVE-2012-3183, CVE-2012-3184, CVE-2012-3185, CVE-2012-3186, CVE-2012-5065

 

6.2

Upgrade to 7.6.1 or later version and apply CPU patch

CVE-2012-3183, CVE-2012-3184, CVE-2012-3185, CVE-2012-3186, CVE-2012-5065

 

6.1

Upgrade to 7.6.1 or later version and apply CPU patch

CVE-2012-3183, CVE-2012-3184, CVE-2012-3185, CVE-2012-3186, CVE-2012-5065

 

3.4.35 Oracle WebCenter Suite

For the appropriate product versions listed below, refer to the corresponding Oracle Fusion Middleware patch availability sections that contain information on Error Correction, and for the patches to apply. Not all homes that are listed in those sections might be present in the Oracle WebCenter Suite installation. Only the relevant homes from those tables need to be patched.

Table 106 describes the available patches for Oracle WebCenter Suite.

Table 106 Patch Availability information for Oracle WebCenter Suite

Product Home

Patches

Comments

Oracle WebCenter Suite 11.1.1.6.0 home

See Section 3.4.13.2, "Patch Availability for Oracle Fusion Middleware 11.1.1.6"

 

Oracle WebCenter Suite 11.1.1.5.0 home

See Section 3.4.13.3, "Patch Availability for Oracle Fusion Middleware 11.1.1.5"

 

3.4.36 Oracle WebLogic Integration

Table 107 describes the Error Correction information for Oracle WebLogic Integration.

Table 107 Error Correction information for Oracle WebLogic Integration

Patch Information

10.3.1.0

9.2.3

Comments

Final Patch

January 2017

October 2013

 

Table 108 describes the availability for Critical Patch Updates for Oracle WebLogic Integration. See also the underlying product stack tables.

Table 108 Critical Patch Update Availability for Oracle WebLogic Integration

Product Home

Patch

Advisory Number

Smart Update Patch Set ID

Smart Update Patch IDs

Comments

10.3.1.0

SPU Patch 14364893

CPU Patch 12875001

CPU Patch 12875006

CPU Patch 12874981

CPU Patch 13583186

CPU Patch 10625676

CPU Patch 13442902

CVE-2011-1411

Released October 2011

Released October 2011

Released October 2011

Released April 2012

Released January 2011

Released January 2012

NA

NA

EXP8

ZVC4

AEQE

QHPL

WT6W

HEYE

RPQH

3QHE, NXQM, 982N, 6BME, 5EGH

EDAT, QR92

VXVR, WSNI, SU7Z, PQVV, ZE59, XW21, VV75

2QSG, E65J

8WHJ, K4VY

WLS 10.3.0.0 CSS patch

WLS 10.3.0.0 JMS patch

WLS 10.3.0.0 WebServices patch

WLS 10.3.0.0 Security patch

WLS 10.3.0.0 WebApp patch

WLS 10.3.0.0 Core patch

WLS 10.3.0.0 Console patch

9.2.3.0

Patch 13705387

Released April 2012

 

 

WebLogic Server 9.2.3.0 is a one-off patch for the WebLogic Server home

3.4.37 Oracle WebLogic Portal

Table 109 describes the Error Correction information for Oracle WebLogic Portal.

Table 109 Error Correction information for Oracle WebLogic Portal

Patch Information

10.3.2.0

10.2.1.0

10.0.1.0

9.2.3.0

Comments

Final Patch

January 2017

January 2015

January 2015

October 2013

 

Table 110 describes the available patches for WebLogic Portal. See also the underlying product stack tables (JRockit and WLS) for any applicable patches.

WebLogic Portal patches are cumulative to include all the prior published advisories. For more information, see My Oracle Support Note 1355929.1, October 2011 Updates Introduce New WebLogic Portal (WLP) Configuration Options for SSL Session ID and SSL Filters.

WebLogic Portal 9.2.3.0 is bundled with WebLogic Server 9.2.3.0, which is out of error correction. Contact Oracle support for security patches needed for WebLogic Server 9.2.3.0

Table 110 Critical Patch Update Availability for WebLogic Portal

Product Home

Patch

Advisory Number

Comments

10.3.2.0

CPU Patch 12388715

Released October 2011

WebLogic Portal patch for WebLogic Portal 10.3.2.0 home

10.3.2.0

SPU Patch 14364893

CPU Patch 12875001

CPU Patch 12875006

CPU Patch 12874981

CPU Patch 13583186

CPU Patch 10625676

CPU Patch 13442902

CVE-2011-1411

Released October 2011

Released October 2011

Released October 2011

Released April 2012

Released January 2011

Released January 2012

WLS 10.3.2.0 CSS patch (Smart Update Patch ID: A6AX)

WLS 10.3.2.0 JMS patch (Smart Update Patch IDs: 9ZW7)

WLS 10.3.2.0 WebServices patch (Smart Update Patch IDs: L8DT)

WLS 10.3.2.0 Security patch (Smart Update Patch IDs: VHAC, R4P6)

WLS 10.3.2.0 WebApp patch (Smart Update Patch IDs: AYDB, 8IWX)

WLS 10.3.2.0 Core patch (Smart Update Patch IDs: H3QP, Y3IR)

WLS 10.3.2.0 Console patch (Smart Update Patch IDs: 1MVX, PAIS)

10.2.1.0

CPU Patch 12388715

Released October 2011

WebLogic Portal patch for WebLogic Portal 10.2.1.0 home

10.2.1.0

SPU Patch 14364893

CPU Patch 12875001

CPU Patch 12875006

CPU Patch 12874981

CPU Patch 13583186

CPU Patch 10625676

CPU Patch 13442902

CVE-2011-1411

Released October 2011

Released October 2011

Released October 2011

Released April 2012

Released January 2011

Released January 2012

WLS 10.0.2.0 CSS patch (Smart Update Patch ID: 1IVL)

WLS 10.0.2.0 JMS patch (Smart Update Patch IDs: 1G6S)

WLS 10.0.2.0 WebServices patch (Smart Update Patch IDs: YQ8T)

WLS 10.0.2.0 Security patch (Smart Update Patch IDs: H9QB, W4G5)

WLS 10.0.2.0 WebApp patch (Smart Update Patch IDs: 6CRM, 1J9G, KEFR, FVXN)

WLS 10.0.2.0 Core patch (Smart Update Patch IDs: I4UY, 1ULW)

WLS 10.0.2.0 Console patch (Smart Update Patch IDs: 288U, ES1

10.0.1.0

CPU Patch 12388715

Released October 2011

WebLogic Portal patch for WebLogic Portal 10.0.1.0 home

10.0.1.0

SPU Patch 14364893

CPU Patch 12875001

CPU Patch 12875006

CPU Patch 12874981

CPU Patch 13583186

CPU Patch 10625676

CPU Patch 13442902

CPU Patch 12818102

CVE-2011-1411

Released October 2011

Released October 2011

Released October 2011

Released April 2012

Released January 2011

Released January 2012

Released October 2011

WLS 10.0.1.0 CSS patch (Smart Update Patch ID: 72CB)

WLS 10.0.1.0 JMS patch (Smart Update Patch IDs: XTNC)

WLS 10.0.1.0 WebServices patch (Smart Update Patch IDs: 4CM9, 6E46, GP9Y)

WLS 10.0.1.0 Security patch (Smart Update Patch IDs: 7IVR, 3HBG)

WLS 10.0.1.0 WebApp patch (Smart Update Patch IDs: E8IH, 1CJH, AFQT, GY9R, QND8, 3Y15, 2J89, VFLA, DITI)

WLS 10.0.1.0 Core patch (Smart Update Patch IDs: ZYSL, 3PPG)

WLS 10.0.1.0 Console patch (Smart Update Patch IDs: WTXU, 4KH5)

WebLogic Server patch for WebLogic Server 10.0.1.0 home

9.2.3.0

CPU Patch 13705391

Released April 2012

WebLogic Server 9.2.3.0 one-off patch that needs to be applied to WebLogic Server home

9.2.3.0

CPU Patch 12388715

Released October 2011

WebLogic Portal patch for WebLogic Portal 9.2.3.0 home

9.2.3.0

CPU Patch 12839749

Released October 2011

WebLogic Server patch for WebLogic Server 9.2.3.0 home

3.4.38 Oracle WebLogic Server and WebLogic Express

Table 111 describes the Error Correction information for Oracle WebLogic Server and WebLogic Express.

Table 111 Error Correction information for Oracle WebLogic Server and WebLogic Express

Patch Information

10.0.2.0

9.2.4.0

Comments

Final Patch

January 2015

October 2013

 

Table 112 describes the available patches for WebLogic Server and WebLogic Express. See also the underlying product stack tables (JRockit) for any applicable patches.

For WebLogic Server releases 10.3.2 and later that are part of the Oracle Fusion Middleware 11g R1 releases, see Section 3.4.13, "Oracle Fusion Middleware."

Table 112 Critical Patch Update Availability for Oracle WebLogic Server and WebLogic Express

Product Home

Patch

Advisory Number

Smart Update Patch Set ID

Smart Update Patch IDs

Comments

Oracle Java SE home

See Oracle Java SE Critical Patch Update

See Oracle Java SE Critical Patch Update

 

 

See Note 1492980.1, How to Maintain the Java SE Installed or Used with FMW 11g Products

Oracle JRockit 28.x home

See Section 3.4.22, "Oracle JRockit"

See Section 3.4.22, "Oracle JRockit"

 

 

 

Oracle WebLogic Server Plug-ins

See Section 3.4.40, "Oracle WebLogic Server Plug-ins"

See Section 3.4.40, "Oracle WebLogic Server Plug-ins"

 

 

See Note 1111903.1, WebLogic Server 10gR3 (10.3.0) and 11gR1 (10.3.x) - Web Server Plug-In Support

10.0.2.0

SPU Patch 14364893

CPU Patch 12875001

CPU Patch 12875006

CPU Patch 12874981

CPU Patch 13583186

CPU Patch 10625676

CPU Patch 13442902

CVE-2011-1411

Released October 2011

Released October 2011

Released October 2011

Released April 2012

Released January 2011

Released January 2012

NA

NA

NA

SPN1

IJ9E

YG16

Z7VC

1IVL

1G6S

YQ8T

H9QB, W4G5

6CRM, 1J9G, KEFR, FVXN

I4UY, 1ULW

288U, ES1Z

CSS Patch

JMS patch

WebServices patch

Security patch

WebApp patch

Core patch

Console patch

9.2.4.0

SPU Patch 14364893

CPU Patch 12875001

CPU Patch 12875006

CPU Patch 12874981

CPU Patch 13583186

CPU Patch 10625676

CPU Patch 13442902

CVE-2011-1411

Released October 2011

Released October 2011

Released October 2011

Released April 2012

Released January 2011

Released January 2012

NA

NA

NA

NA

UYPQ

YCI8

6G3Q

8VK7

GNSG

MFVW

8D9U

DVTI, 581S

V4MI

NNFB, XZYH

CSS Patch

JMS patch

WebServices patch

Security patch

WebApp patch

Core patch

Console patch

3.4.39 Oracle WebLogic Server

Table 113 describes the Error Correction information for Oracle WebLogic Server.

Table 113 Error Correction information for Oracle WebLogic Server Patch Set Update

Patch Information

12.1.1.0

10.3.6.0

10.3.5.0

Comments

Final Patch

-

-

July 2013

 

Table 114 describes the available patches for Oracle WebLogic Server.

Table 114 Patch Set Update Availability for Oracle WebLogic Server

Product Home

Patch

Advisory Number

Comments

Oracle Java SE home

See Oracle Java SE Critical Patch Update

See Oracle Java SE Critical Patch Update

See Note 1492980.1, How to Maintain the Java SE Installed or Used with FMW 11g Products

Oracle JRockit 28.x home

See Section 3.4.22, "Oracle JRockit"

See Section 3.4.22, "Oracle JRockit"

 

Oracle WebLogic Server Plug-ins

See Section 3.4.40, "Oracle WebLogic Server Plug-ins"

See Section 3.4.40, "Oracle WebLogic Server Plug-ins"

See Note 1111903.1, WebLogic Server 10gR3 (10.3.0) and 11gR1 (10.3.x) - Web Server Plug-In Support

WebLogic Server 12.1.1.0 home

PSU 12.1.1.0.2 Patch 14331523

CVE-2011-1411

See Note 1306505.1, Announcing Oracle WebLogic Server PSUs (Patch Set Updates)

WebLogic Server 10.3.6.0 home

PSU 10.3.6.0.2 Patch 14331527

CVE-2011-1411

See Note 1306505.1, Announcing Oracle WebLogic Server PSUs (Patch Set Updates)

WebLogic Server 10.3.5.0 home

PSU 10.3.5.0.5 Patch 14331529

CVE-2011-1411

See Note 1306505.1, Announcing Oracle WebLogic Server PSUs (Patch Set Updates)

WebLogic Server 10.3.5.0 home

SPU Patch 14681306

CVE-2012-3137

Oracle JDBC Patch. See Note 1493990.1, Patching for CVE-2012-3137 prior to installing this SPU patch

3.4.40 Oracle WebLogic Server Plug-ins

Table 115 describes the available patches for Oracle WebLogic Server Plug-ins (Apache/IIS/iPlanet).

The WebLogic plug-ins include all cumulative bug fixes and thus include fixes for all previously released advisories. For more information, see My Oracle Support Note 1111903.1.

Table 115 Critical Patch Update Availability for Oracle WebLogic Server Plug-ins

Product Home

Patch

Advisory Number

Comments

1.0

CPU Patch 11845433

Released April 2011

See Note 1111903.1, WebLogic Server Web Server Plug-In Support

1.1

CPU Patch 9893736

Released July 2010

See Note 1111903.1, WebLogic Server Web Server Plug-In Support

3.4.41 Oracle WebLogic SIP Server

Table 116 describes the Error Correction information for Oracle WebLogic SIP Server.

Table 116 Error Correction information for Oracle WebLogic SIP Server

Patch Information

3.x

2.x

Comments

Final Patch

October 2013

April 2013

 

Table 117 describes the available patches for Oracle WebLogic SIP Server. See also the underlying product stack tables for any applicable patches. See the Comments column on how to apply the patch to the product home.

Table 117 Patch Availability for Oracle WebLogic SIP Server

Oracle WebLogic SIP Server

Patch

Advisory Number

Comments

3.1.1.0

CPU Patch 13705098

Released April 2012

WebLogic Server 9.2.3.0 one-off patch that needs to be applied to WebLogic Server home

3.1.0.0

CPU Patch 13705098

Released April 2012

WebLogic Server 9.2.1.0 one-off patch that needs to be applied to WebLogic Server home

3.0.0.0

CPU Patch 13705098

Released April 2012

WebLogic Server 9.2.0.0 one-off patch that needs to be applied to WebLogic Server home

2.2.0.0

CPU Patch 13705098

Released April 2012

WebLogic Server 8.1.5.0 one-off patch that needs to be applied to WebLogic Server home

2.1.0.0

CPU Patch 13705098

Released April 2012

WebLogic Server 8.1.5.0 one-off patch that needs to be applied to WebLogic Server home

2.0.2.0

CPU Patch 13705098

Released April 2012

WebLogic Server 8.1.4.0 one-off patch that needs to be applied to WebLogic Server home

3.4.42 Oracle Workshop for WebLogic

Table 118 describes the Error Correction information for Oracle Workshop for WebLogic.

Table 118 Error Correction information for Oracle Workshop for WebLogic

Patch Information

9.2.3.0

Comments

Final Patch

October 2013

 

Table 119 describes the available patches for Oracle Workshop for WebLogic. See also the underlying product stack tables for any applicable patches. Refer to comments section and apply the patch to the respective product home.

Table 119 Patch Availability for Oracle Workshop for WebLogic

Oracle Workshop for WebLogic

Patch

Advisory Number

Comments

9.2.3.0

CPU Patch 13705400

Released April 2012

WebLogic Server 9.2.3.0 one-off patch that needs to be applied to WebLogic Server home

3.5 Tools

This section contains the following:

·         Section 3.5.1, "Oracle Opatch"

3.5.1 Oracle Opatch

Table 120 describes the minimum product requirements for Oracle OPatch. The CPU security vulnerabilities are fixed in the listed release and later releases. The Oracle OPatch downloads can be found at Patch 6880880.

Table 120 Minimum Product Requirements for Oracle OPatch

Component

Release

Advisory Number

Comments

Oracle OPatch

1.0.0.0.64

Announced July 2011

 

4 Final Patch History

Table 121 describes the final patch history.

The final patch is the last CPU/PSU release for which the product release is under error correction. For more information, see My Oracle Support Note 209768.1, Database, FMW, EM Grid Control, and OCS Software Error Correction Support Policy.

Table 121 Final Patch History

Release

Final Patches

Comments

January 2013

Oracle Business Intelligence Enterprise Edition 11.1.1.5.0

Oracle Business Intelligence Publisher 11.1.1.5.0

Oracle Complex Event Processing and WebLogic Event Server 11.1.1.4.0

Oracle Database 10.2.0.4 for HP Open VMS-Alpha, and VMS-Itanium

Oracle Database 10.2.0.3 for IBM z/OS on System z

Oracle Event Processing 11.1.1.4.0

Oracle FatWire Content Server (including Satellite Server) 7.5

Oracle FatWire Content Server (including Satellite Server) 7.0.3

Oracle FatWire Content Server (including Satellite Server) 7.0.2

Oracle FatWire Content Server (including Satellite Server) 7.0.1

Oracle FatWire Content Server (including Satellite Server) 7.0

Oracle FatWire Content Server (including Satellite Server) 6.3.x

Oracle FatWire Content Server (including Satellite Server) 6.2

Oracle FatWire Content Server (including Satellite Server) 6.1

Oracle Fusion Middleware 11.1.1.5.0

Oracle Fusion Middleware 11.1.1.4.0 for Portal, Forms, Reports and Discoverer

Oracle Map Viewer 11.1.1.5.0

 

October 2012

Oracle AquaLogic Interaction Logging Utilities 6.0

Oracle AquaLogic Interaction Logging Utilities 1.0

Oracle COREid 10.1.4.3

Oracle SSO/DAS 10.1.4.3

Oracle Secure Backup 10.3.0.3

 

July 2012

AquaLogic Data Services Platform 2.5.2.0

Oracle Business Intelligence Enterprise Edition 11.1.1.3

Oracle Business Intelligence Enterprise Edition 10.1.3.4.1

Oracle Business Publisher 11.1.1.3

Oracle Business Publisher 10.1.3.4.1

Oracle Outside In Technology 8.3.5

Oracle Service Bus 2.6.1.0

 

April 2012

Oracle Fusion Middleware 11.1.1.4 except Portal, Forms, Reports and Discoverer

Oracle WebLogic Server 10.3.4.0

 

January 2012

Hyperion Enterprise Performance Management 9.3.x

Oracle Database 10.1.0.5

Oracle Enterprise Manager Grid Control 10.1.0.6

Oracle Fusion Middleware 11.1.1.3

Oracle WebLogic Server 10.3.3.0

Secure Enterprise Search 10.1.8.4

 

October 2011

Oracle Fusion Middleware 10.1.2.3

Oracle Identity Management 10.1.4.3, except for Oracle Single Sign-on and Delegated Administration Services working with Oracle Internet Directory 11gR1 for user authentication of Portal 11gR1, Forms 11gR1, Reports 11gR1 and Discoverer 11gR1 Middleware 11g PFRD installations

Oracle Identity Management 10.1.4.0.1

Oracle Identity Management 9.0.x

Oracle Portal 10.1.4.2

Oracle Workflow Server 2.6.3.5

 

July 2011

Oracle Beehive 1.5.1.x

Oracle Database 11.2.0.1

Oracle Database 10.2.0.4

Oracle Outside In Technology 8.3.2

Oracle Database 10.2.0.4 excludes Oracle Solaris x86 (32-bit), Apple Mac OS X, HP Open VMS-Alpha, and VMS-Itanium

April 2011

Oracle Business Process Management 5.7.3

Oracle Fusion Middleware 11.1.1.2

 

October 2010

Oracle Fusion Middleware 11.1.1.1

 

5 Sources of Additional Information

The following documents provide additional information about Critical Patch Updates:

·         My Oracle Support Note 1477868.1, Critical Patch Update October 2012 Database Patch Security Vulnerability Molecule Mapping

·         My Oracle Support Note 1477865.1, Critical Patch Update October 2012 Database Known Issues.

·         My Oracle Support Note 1477743.1, Critical Patch Update October 2012 Known Issues for Oracle Enterprise Manager Grid Control.

·         My Oracle Support Note 1477742.1, Critical Patch Update October 2012 Oracle Fusion Middleware Known Issues.

·         My Oracle Support Note 1365205.1, Getting Started with Oracle WebLogic Server: How to Make Sure that Recommended Patches are Applied

·         My Oracle Support Note 1314535.1, Announcing Exalogic PSUs (Patch Set Updates)

·         My Oracle Support Note 1306505.1, Announcing Oracle WebLogic Server PSUs (Patch Set Updates)

·         My Oracle Support Note 1227443.1, Patch Set Updates Known Issues Notes

·         My Oracle Support Note 854428.1, Patch Set Updates (PSUs) for Oracle Products.

·         My Oracle Support Note 605795.1, Introduction to catbundle.sql.

·         My Oracle Support Note 605398.1, How To Find The Version Of The Main EM Components.

·         My Oracle Support Note 559534.1, Applying Critical Patch Updates to Collaboration Suite 10g.

·         My Oracle Support Note 438314.1, Critical Patch Update - Introduction to Database n-Apply CPU Patches.

·         My Oracle Support Note 405972.1, Oracle Application Server 10g Examples for Critical Patch Updates.

·         My Oracle Support Note 209768.1, Database, FMW, EM Grid Control, and OCS Software Error Correction Support Policy.

·         My Oracle Support Note 161549.1, Oracle Database Server and Networking Patches for Microsoft Platforms.

6 Modification History

Table 122 describes the modification history for this document.

Table 122 Modification History

Date

Modification

28 November 2012

·         Updated Table 71

12 November 2012

·         Updated Section 2.10

·         Updated Section 2.7

·         Updated Table 121

6 November 2012

·         Added Section 3.4.36

5 November 2012

·         Updated Section 2.10

·         Added Section 2.5

·         Added Section 2.6

·         Updated Section 2.7

·         Updated Table 15

·         Updated Table 16

·         Updated Table 18

·         Updated Table 121

30 October 2012

·         Updated Table 10

25 October 2012

·         Updated Table 8

24 October 2012

·         Updated Table 69

23 October 2012

·         Updated Section 2.10

22 October 2012

·         Updated Table 65, Table 67, Table 69, Table 71, Table 112, Table 114

17 October 2012

·         Updated Table 15

16 October 2012

·         Released

7 Documentation Accessibility

For information about Oracle's commitment to accessibility, visit the Oracle Accessibility Program website at http://www.oracle.com/pls/topic/lookup?ctx=acc&id=docacc.

Access to Oracle Support

Oracle customers have access to electronic support through My Oracle Support. For information, visit http://www.oracle.com/pls/topic/lookup?ctx=acc&id=info or visit http://www.oracle.com/pls/topic/lookup?ctx=acc&id=trs if you are hearing impaired.


Patch Set Update and Critical Patch Update October 2012 Availability Document