« To SSL or not to SSL | Main | Essbase Server Clustering »
Thursday
Feb022012

Oracle Security Alert for CVE-2011-5035

This alert from Oracle addresses a specific type of Denial of Service attack to WebLogic only.  No data is at risk and the alert specifically notes that malicious users won’t be able to access the environment.  However, during the attack (like any Denial of Service attack), normal users will be unable to access the environment as well.
 
A set of WebLogic patches have been released to addressed the issue.  However, since the overall risk is very low to the average Hyperion users, application of this patch is does not need to be a high priority unless the WebLogic server is publicly accessible (not firewalled).  WebLogic patch ID is 13583186 and has only been publically available for one week.

--Author, Tony Moyers

PrintView Printer Friendly Version

EmailEmail Article to Friend

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.
Member Account Required
You must have a member account on this website in order to post comments. Log in to your account to enable posting.