Oracle has released another monster quarterly security update containing 136 fixes for flaws in a wide range of products. The biggest change is the adoption of the Common Vulnerability Scoring System (CVSS) version 3.0, which more accurately reflects the impact of flaws than CVSS 2.0. The new rating system might affect Oracle patch prioritization inside organizations. Oracle products that have vulnerabilities rated as high and critical (score 9.0 to 10.0) are Oracle Database Server, E-Business Suite, Fusion Middleware, Oracle Sun Products, Java and MySQL.”]

