Skip to main content

Oracle Releases Security Bulletin

Oracle has released its Critical Patch Update for October 2017 to address 252 vulnerabilities across multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Oracle has released its Critical Patch Update for October 2017 to address 252 vulnerabilities across multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.

Threat details

Update

Threat actors have been observed exploiting a known vulnerability in WebLogic Server versions up to 12.2.1.2.0 to deliver cryptocurrency mining malware. This Critical Patch Update resolves the vulnerability.

Update

Attackers continue to exploit this vulnerability to spread cryptocurrency mining malware. The latest malware also attempts to gather Secure Shell (SSH) keys, hosts and accounts in order to propagate across the infected network.


Threat updates

Date Update
16 Feb 2018

Threat actors have been observed exploiting a known vulnerability in WebLogic Server versions up to 12.2.1.2.0 to deliver cryptocurrency mining malware. This Critical Patch Update resolves the vulnerability.


Remediation steps

Type Step

Users and administrators are encouraged to review the "Oracle October 2017 Critical Patch Update" and apply the necessary updates.

 


Last edited: 17 February 2020 11:36 am