Latest Comments
"Excellent info. If you use Gumtree Australia you will see many obvious scam posts in all ..."
by Marian Imrie | Dec 5, 2008 4:45 PM
 
"Very nice and useful information. UT4B4. Tape4backup.com"
by Lto-4 Tape | Dec 4, 2008 9:23 PM
 
"Interesting that you do not bother to list the one AV that has consistently passed the VB100. ..."
by Ben | Dec 4, 2008 6:00 PM
 
"I like this"
by nanwin | Dec 3, 2008 3:05 PM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM

Oracle closes 41 vulnerabilities, 17 in its database

  • Email a Friend
  • Print Page
By Jim Carr
Apr 17, 2008 10:03 AM
Tags: Oracle | closes | 41 | vulnerabilities, | 17 | in | its | database
This amounts to a "medium sized" patch cycle for Oracle, Amichai Shulman, chief technology officer at database security vendor Imperva, told SCMagazineUS.com.

In addition to the database product, Oracle released 11 fixes for its Business Suite and associated applications, six for the Oracle Siebel Enterprise Suite and three each for its Application Server and PeopleSoft-JDEdwards Suite. It also fixed bugs in its Enterprise Manager, Enterprise Search/Ultrasearch product and Collaboration Suite.

Fourteen of the vulnerabilities can be exploited remotely without authentication, the company said in its security alert. These include seven affecting the E-Business Suite, three impacting the Siebel Enterprise product, two impacting the Oracle Application Server, one each affecting the Oracle database and the Application Express product.

Exploiting these bugs would allow an attacker to take over the affected system via a network without needing a username or password, the company said.

“This basically means that your database is a sitting duck unless you deploy this patch," Slavik Markovich, CTO of Sentrigo, told SCMagazineUS.com. "The last we saw of those was, I believe, two CPUs ago."

Shulman said one of the database vulnerabilities fixed in this round allows an outside attacker to perform an activity in the database server without the activity being reported by the internal audit trail mechanism.

"That's an example of why enterprises should start using external auditing mechanisms for their database servers," he said. “There will always be vulnerabilities in the software products enterprises are trying to protect and they can't rely just on the internal auditing mechanisms.”

Oracle rated one of the Application Server vulnerabilities a 9.3 (out of 10) on its vulnerability scoring system. This flaw, which is applicable to client-only installations, affects only the client portion of Oracle Application Server, according to Oracle. Most of the remaining vulnerabilities were of low to medium in severity, the company said.

All six of the Siebel Enterprise security fixes are for the product's SimBuilder component. SimBuilder is a standalone component used to prepare and deliver training materials and may not be deployed in all Siebel enterprise installations, Oracle said.

Oracle has on several occasions, including this round, found multiple instances of a single vulnerability within its products and patched them separately instead of fixing them through the package completely, Imperva's Shulman said.

"In a quick search, I found five of those when they fixed only part of the problem, he said, adding that time constraints likely are to blame for this approach.



See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Patch Management Whitepapers