LICENSEWARE

Oracle America, Inc. v. Terix and v. Hewlett Packard Enterprise (Solaris patches)

This article is about two related cases in the Northern District of California over third-party support providers' use of Oracle Solaris patches on servers without an Oracle support contract. It summarises the court records and is not legal advice.

On This Page

Oracle America, Inc. v. Terix and Oracle America, Inc. v. Hewlett Packard Enterprise are two related copyright cases in the United States District Court for the Northern District of California. Oracle alleged that third-party support providers had downloaded and installed patches for its Solaris operating system on customer servers that were not covered by an Oracle support contract. Terix and its affiliates agreed in 2015 to a stipulated judgment requiring them to pay Oracle $57,723,000 and accept a permanent injunction.[2] In the case against HPE, which had subcontracted Solaris support to Terix, the Ninth Circuit revived Oracle’s claims in 2020, a jury found HPE liable in June 2022, and the parties stipulated to dismiss the case in January 2023.[3][5][6]

Background

As described by the Ninth Circuit, Oracle has owned registered copyrights in Solaris since it acquired Sun Microsystems in January 2010, and various Solaris patches also contain registered code. Oracle licenses Solaris to a customer when the customer buys a server with the software preinstalled. The Binary Code License Agreement applies to Solaris 8 and 9, the Software License Agreement applies to Solaris 10, and Solaris 11 is governed by a similar licence.[3]

Customers with a prepaid annual Oracle support contract can reach Solaris patches through the password-protected My Oracle Support website. A customer must place every server for which it wants support on an active support contract, and must accept further terms of use when it accesses the site. The court noted that Oracle had ended Sun’s practice of releasing security patches, firmware updates and new Solaris versions free of charge.[3] In the Terix case, the district court summarised Oracle’s allegations that support customers receive a Customer Support Identification (CSI) number linked to the products covered by the contract, and that a customer “may not share or use its access credentials for the benefit of others or for the benefit of unsupported Oracle hardware”.[1]

The dispute

Terix (filed 2013). Oracle sued Terix and Maintech on 19 July 2013 for copyright infringement, violations of the Computer Fraud and Abuse Act (CFAA), false advertising under the Lanham Act, breach of contract, intentional interference and unfair competition.[1][7] Oracle alleged that the defendants told customers they could lawfully provide Solaris updates, or that customers were entitled to updates without an Oracle support contract by virtue of their Solaris licences, and that they obtained support credentials under false pretences or directed others to download patches.[1] In January 2014 the court dismissed Oracle’s password-trafficking claim under 18 U.S.C. § 1030(a)(6) with leave to amend, but allowed the CFAA access claims and the interference and unfair competition claims to proceed. It distinguished access by customers who had some rights, however limited, from access by the defendants themselves, who were alleged to have no access rights at all.[1] Terix counterclaimed under the Sherman Act and California law.[2]

HPE (filed 2016). HPE ran a multi-vendor support business and subcontracted indirect support for Solaris servers to Terix. According to the Ninth Circuit, for joint HPE-Terix customers Terix arranged Oracle support for a single server in the customer’s name, created a My Oracle Support credential for it, and used the credential to download patches for use on servers that were not under contract, the so-called “one-to-many” scheme. Where a customer was not yet supported, Terix created credentials using fictitious names, email addresses and credit cards.[3] After the Terix case, Oracle and HPE agreed to toll the limitation period from 6 May 2015, and Oracle sued HPE in March 2016 for copyright infringement, intentional interference and unfair competition. HPE asserted, among other defences, express and implied licence.[3]

Decision or outcome

Terix. In May 2015 the court granted summary judgment for Oracle on Terix’s licence defence. As quoted by the Ninth Circuit, the magistrate judge reasoned that Terix “violated the terms of the relevant licenses by using a customer’s credential’s to … download patches for any number of that customer’s machines, whether covered by the license terms or not”.[3] On 10 June 2015 the court entered a stipulated judgment under which Terix Computer Company, Sevanna Financial and West Coast Computer Exchange pay Oracle $57,723,000 and are permanently enjoined from providing Oracle/Sun software and support materials, including Solaris patches and firmware, other than materials Oracle has made public. Terix may not log into password-protected Oracle websites for itself or for customers, must give its customers a court-ordered statement that it is not an Oracle partner and has no right to provide Oracle software or updates, and must allow Oracle an annual audit of its Oracle/Sun hardware work for five years. Terix’s counterclaims took nothing, and the parties waived appeal.[2] Oracle’s claims against Maintech were resolved by a separate stipulated judgment and settlement.[2][7]

HPE. The district court granted summary judgment for HPE. On 20 August 2020 the Ninth Circuit affirmed in part and reversed in part.[3] It held that the copyright claims were barred for conduct before 6 May 2012, because Oracle had suspicions about Terix and HPE from 2010 and so had a duty to investigate. It reversed on infringement: the district court had read Oracle’s support contracts as licensing the customer, or its agent, to download, deliver and install patches, and had considered only installations, but it had “never identified a license provision that authorized the challenged pre-installation conduct”. The Ninth Circuit remanded for the licences to be construed and for the claims about downloading and copying to be reconsidered.[3] In a separate memorandum it also revived Oracle’s interference claims, observing that Oracle support customers had at least two contracts, a support contract and an agreement for accessing software patches.[4]

On 14 June 2022 a jury found that HPE had directly and vicariously infringed Oracle’s copyrights (but not contributorily), that Terix had directly infringed, and that HPE had intentionally interfered with Oracle’s contractual and prospective economic relationships. It awarded $30 million for copyright infringement and $24 million for the interference claims, and found no malice, oppression or fraud.[5] Oracle then moved for a permanent injunction and HPE for judgment as a matter of law or a new trial. On 17 January 2023, before those motions were decided, the court granted the parties’ stipulation of voluntary dismissal.[6]

Significance for software licensing and SAM practice

The cases concern software that ships with hardware. The Solaris licence came with the server, but, as the courts described Oracle’s model, patches were available only through a support contract that had to cover each server, and the support site had its own terms of use.[3] Under that model an organisation’s entitlement to a patch depends on its support position for the specific machine, not only on its licence to the operating system. Oracle’s current support terms are described in Oracle technical support policies.

The Ninth Circuit’s opinion also shows that downloading and copying patches, and not only installing them, may be infringing if no licence term authorises it.[3] Similar questions about third-party support arose in Oracle v. Rimini Street and Oracle v. SAP (TomorrowNow).

Lessons learned

  • Patch rights follow the support contract, server by server. Oracle required every server for which support was wanted to be on an active contract, and the court in the Terix case held that using a customer’s credentials to download patches “for any number of that customer’s machines” was outside the licence terms.[3] Keep records of which servers are under support and which patches were applied to them.
  • Ask third-party providers how they obtain updates. Terix’s court-ordered statement to customers said it was not an Oracle partner and had no legal right to provide Oracle software or bug fixes, and HPE was found liable for infringement and interference through its subcontracting arrangement.[2][5] A customer’s own support contract and access terms may be breached by what its provider does on its behalf.[4]
  • Suspicion triggers a duty to investigate. Oracle lost its copyright claims for conduct before 6 May 2012 because it had concerns about the one-to-many practice from 2010 and did not investigate reasonably.[3] The same rule of accrual applies to any party that suspects a copyright problem and waits.

References

  1. Oracle America, Inc. v. Terix Computer Co., No. 5:13-cv-03385-PSG, order granting-in-part defendants' motions to dismiss (N.D. Cal. Jan. 3, 2014), Dkt. 61Magistrate Judge Paul S. Grewal; describes Oracle's allegations and the CSI-based access to supportEffective 2014-01-03. Retrieved 2026-09-30.
  2. Oracle America, Inc. v. Terix Computer Co., stipulated judgment (N.D. Cal. June 10, 2015), Dkt. 652Monetary award, permanent injunction, annual audit for five years, Exhibit A customer statementEffective 2015-06-10. Retrieved 2026-09-30.
  3. Oracle America, Inc. v. Hewlett Packard Enterprise Co., No. 19-15506, opinion (9th Cir. Aug. 20, 2020)Published opinion by Judge Milan D. Smith, Jr.; statute of limitations and copyright infringement claimsEffective 2020-08-20. Retrieved 2026-09-30.
  4. Oracle America, Inc. v. Hewlett Packard Enterprise Co., No. 19-15506, memorandum disposition (9th Cir. Aug. 20, 2020)Not for publication; state law interference and unfair competition claimsEffective 2020-08-20. Retrieved 2026-09-30.
  5. Oracle America, Inc. v. Hewlett Packard Enterprise Co., No. 16-cv-01393-JST, verdict form (N.D. Cal. June 14, 2022), Dkt. 1349Effective 2022-06-14. Retrieved 2026-09-30.
  6. Oracle America, Inc. v. Hewlett Packard Enterprise Company, No. 4:16-cv-01393 (N.D. Cal.), docketPACER-derived docket; entries 1358-1359 (post-trial motions), 1393-1394 (stipulation and order of voluntary dismissal, 2023-01-17)Retrieved 2026-09-30.
  7. Oracle America, Inc. v. Terix Computer Company, Inc., No. 4:13-cv-03385 (N.D. Cal.), docketPACER-derived docket; filed 2013-07-19, terminated 2015-06-10; entry 653 (good faith settlement determination for Maintech, 2015-06-12)Retrieved 2026-09-30.

See also

Esc