Oracle has released a patch for a server flaw that can be exploited over a network without the use of a username or password.

Source: http://news.zdnet.com/2424-9595_22-391116.html