Oracle Security Alert for CVE-2011-5035
Thursday, February 2, 2012 at 11:58AM This alert from Oracle addresses a specific type of Denial of Service attack to WebLogic only. No data is at risk and the alert specifically notes that malicious users won’t be able to access the environment. However, during the attack (like any Denial of Service attack), normal users will be unable to access the environment as well.
A set of WebLogic patches have been released to addressed the issue. However, since the overall risk is very low to the average Hyperion users, application of this patch is does not need to be a high priority unless the WebLogic server is publicly accessible (not firewalled). WebLogic patch ID is 13583186 and has only been publically available for one week.
--Author, Tony Moyers
Infrastructure,
Oracle EPM,
Oracle Fusion in
Infrastructure 
Reader Comments