Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Oracle Critical Patch Update Program, SAP security note 850306

Description

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
This note is issued as a Hot News. Check the note regularly for updates. Otherwise, you will not be aware of important changes regarding prerequisites, consequences and solutions. A new Hot News is not issued if a note is updated.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

General notes for Oracle Critical Patch Updates (CPU)

New as of May 2010: As of the patch day on May 10, 2010, explicit CPU patches will no longer be provided for UNIX platforms. The CPU patches will be contained in a Patch Set Update (PSU) in future. The PSUs will be available every four months, similar to the CPUs.
PSUs will be available in an SAP Bundle Patch (SBP).

New as of 2005: Since 2005, Oracle has provided Critical Patch Updates (CPU) for all product lines on a quarterly basis. The extensive patches contain corrections for significant security problems. You (as the customer) must install these patches unless they collide with another patch that SAP considers to be a mandatory requirement.

New as of Release 10.2.0.4: As of Release 10.2.0.4, the procedure for setting up CPUs has changed fundamentally. Oracle is changing the CPU patch procedure to “n-apply”. This means that the CPU patch now contains only pure security patches, and no longer contains functional patches. If a conflict occurs when you apply the CPU patch, Oracle Support provides a merge patch for the patch that causes the conflict. However, since only security patches are contained in the CPU patch, patch conflicts are much less likely to occur.

As of Oracle Version 10.2.0.4, CPU patches no longer consist of one single large merge patch (which was the case for earlier versions), but they consist of several “patch molecules” that are independent of each other. In principle, a patch molecule is like a single patch and can either be installed completely or not at all. If there is a conflict between a patch that was already installed and a patch molecule that is contained in the CPU, the DBA can either decide not to install the CPU at all, or to install at least those patch molecules that do not cause a conflict. The patch molecules that cause the conflict will be installed at a later time when the merge patch is available.

The advantage of this new procedure is that patch conflicts are less likely to occur. If a patch conflict still occurs, this does not prevent the entire CPU from being installed. Instead, it only prevents the affected patch molecule from being installed. However, due to technical problems, the system may not be able to perform a merge. In this situation, as before, the customer must decide whether to apply the CPU patch or the functional patch that was already recommended.

We do not support the installation of CPU patches using MOPatch (Note 1027012).

Available fix and Supported packages

Affected component

    BC-DB-ORA
    Oracle

CVSS

Score: 0

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/850306

TAGS

#CPU
#Oracle
#security-patches
#patch
#Critical-Patch-Updates

More to explorer

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.