Oracle has released it’s latest CPU (Critical Patch Update) for the last quarter of 2012.
This means admins and DBAs everywhere will be currently rolling out the latest patches to all of their DEV and QA environments to see what has changed and no longer works.
Link to the Oracle official announcement:
Of particular interest is CVE-2012-3220 (see: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-3220 ) which is a vulnerability that looks to allow privilege escalation and access to the underlying OS and affects all latest versions of the Oracle Database.
The below article at threatpost.com has a lot more information on specific updates and some great discussion on particular patches: