Oracle s January 2015 Critical Patch Update includes a fix for a backdoor found in the Oracle E-Business Suite by researcher David Litchfield. The patch is among 169 released in the CPU. Oracle also announced that it was disabling the use of SSL 3.0, calling it an obsolete protocol that was only aggravated by the POODLE fallback vulnerability. Oracle said in its CPU advisory that the vulnerability is not remotely exploitable and merited a criticality rating of 6.0 out of 10.
Source: https://threatpost.com/oracle-patches-backdoor-vulnerability-recommends-disabling-ssl/110555/

