But Storms blasted Oracle's communication skills. "Talk to the hand for the [security] PR team," he said. "Oracle is so horrible at security PR, unless they want to let you know that their products are supposedly unbreakable."
Until today, Oracle had refused to comment on the bugs or the in-the-wild exploits.
Users can obtain the emergency update from Oracle's website.
Lucian Constantin, of the IDG News Service, contributed to this report.
Sign up for CIO Asia eNewsletters.