Home > Security News > Oracle patches serious holes with latest CPU
Security News:
EMAIL THIS

Oracle patches serious holes with latest CPU

By Robert Westervelt, News Editor
16 Jan 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Oracle Corp. on Tuesday released its Critical Patch Update fixing vulnerabilities across its database and application product lines.

The IT security guys may not be quite aware of what's going on in the database side.
Slavik Markovich,
chief technology officer, Sentrigo

Redwood Shores, Calif.-based Oracle said it's security update contained patches for 27 flaws, including eight flaws in Oracle Database, and six new security fixes for Oracle Application Server.

The more threatening database flaws included several SQL injection vulnerabilities and an XML DB handling error that could be exploited by an attacker without any special privileges, said Amichai Shulman, chief technology officer of Foster City, Calif.-based Imperva Inc. XML DB is a feature that provides native XML storage and retrieval technology within Oracle database.

The focus of this particular CPU should be on client side vulnerabilities, Shulman said. Five of the application server vulnerabilities may be remotely exploitable without authentication.

A problem with Oracle Jinitiator is one of the most critical vulnerabilities, Shulman said. Jinitiator enables end users to run Oracle Developer Server applications directly within Netscape Navigator or Internet Explorer on the Windows95/98/2000 and Windows NT4.0 platforms.

In addition, flaws were repaired in Oracle Collaboration Suite, Oracle E-Business Suite, Oracle Enterprise Manager and Oracle PeopleSoft Enterprise products.

Meanwhile a new survey suggests that Oracle database administrators are failing to deploy patches. The survey however is far from scientific and some IT pros believe the results may be skewed.

Oracle Critical Patch Update:
Oracle's July 2007 CPU has 45 security fixes: Oracle stuffed 45 security updates into its July 2007 CPU, fixing flaws across its product line attackers could exploit remotely to compromise corporate databases.

Oracle to patch 37 flaws: Database giant Oracle Corp. offered a preview of its April Critical Patch Update (CPU). Fixes are planned for 37 flaws across its product line.

The survey, conducted by Woburn, Mass.-based database security vendor, Sentrigo and polled 305 Oracle database administrators from 14 Oracle user groups between August 2007 and January 2008.

The vendor asked if the DBAs ever applied an Oracle CPU. The vendor said 206 out of those surveyed said they had never applied any Oracle CPUs. Only 31 said they installed the most recent security update from Oracle.

Slavik Markovich, chief technology officer at Sentrigo, said DBAs are ignoring CPUs for a variety of reasons. It is difficult to test and deploy updates without disrupting systems, he said.

"Oracle is the most complicated database with the most features and this makes its attack surface much larger," he said.

Markovich said the results of the survey are startling. In many cases, system stability and uptime may be trumping security, he said.

"The IT security guys may not be quite aware of what's going on in the database side," he said. "They think everything's being applied, but it's not."

Industry experts say its unclear whether the respondents in the survey are DBAs with Oracle databases in a production environment. For example, DBAs within a software development organization would not need to deploy patches right away. Most firms with multiple production databases are bound by compliance regulations to have a patching cycle, said Imperva's Shulman.

"I'm certain that vast majority of DBAs do not apply patches as they go out, because our surveys show that they are usually six to 12 months between patch cycles," Shulman said.



Tags: Database Security ManagementSecurity Patch ManagementVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Database Security Management
Oracle to buy Sun Microsystems for $7.4 billion
Oracle issues 43 updates, fixes serious database flaws
Information security book excerpts and reviews
Kaspersky website hacked multiple times, expert says
Kaspersky website hacked, customer activation codes exposed
SQL injection attacks targeting Flash, JavaScript errors
Fuzzing tool helps Oracle DBAs defend against SQL injection
Oracle extends Audit Vault third-party database compatibility
When should a database application be placed in a DMZ?
Oracle patches dangerous WebLogic, Secure Backup vulnerabilities
Database Security Management Research

Security Patch Management
Adobe patches ColdFusion vulnerability blocking website attack
Microsoft to address DirectShow, ActiveX zero-day flaws
Adobe fixes critical Shockwave Flash Player flaw
Mozilla patches 11 Firefox security flaws, JavaScript errors
Microsoft patches WebDAV security vulnerability in bevy of updates
Adobe issues first quarterly patch release fixing 13 flaws
Microsoft plans 10 security updates, fixing IE, Word, Excel vulnerabilities
Adobe shifts to Microsoft patching process, incident response plan
Software delivery could fix software patching issues
Microsoft updates Office to address serious PowerPoint vulnerabilities

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
data encryption/decryption IC  (SearchSecurity.com)
International Data Encryption Algorithm  (SearchSecurity.com)
link encryption  (SearchSecurity.com)
MD2  (SearchSecurity.com)
MD4  (SearchSecurity.com)
MD5  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts