Oracle released the Pre-Release Announcement for the Oracle CPU October 2011. The upcoming CPU will fix 4 issues in the Oracle database:
- Application Express
- Core RDBMS
- Database Vault
- Oracle Text
The highest CVSS value is 6.5 (normally a SQL Injection vulnerability). None of the issues is remote exploitable.