Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • Database

    Oracle Delivers First Monthly Patch Rollup

    Written by

    Lisa Vaas
    Published August 31, 2004
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Oracle on Tuesday delivered its first-ever monthly rollup of security patches, addressing more than 30 vulnerabilities discovered by Next Generation Security Software Ltd. between January and February, and also tackling more than 20 vulnerabilities that eWEEK.com has learned were recently discovered by Application Security Inc.

      Oracle Corp. issued notice of the patches late in the day, narrowly making its promised deadline of delivering the first rollup Aug. 31 after weeks of saying little about the security flaws.

      /zimages/4/28571.gifClick here to read more about the 30-plus vulnerabilities found at the beginning of the year.

      The older patches cover a plethora of vulnerabilities, including the spectrum of NGSS-discovered flaws such as vulnerability to buffer overflow attacks and SQL injection techniques for gaining access to Oracle databases, as well as ASIs newfound flaws, four of which are deemed high risk.

      Eric Gonzales, co-founder and director of marketing at New York-based ASI, told eWEEK.com that one of the newly discovered flaws allows remote attackers to take advantage of a known, default user account and password. Other flaws allow the database to be exploited by a regular user, who can crash the database or escalate his or her privileges to administrator level.

      /zimages/4/28571.gifOracle was silent about the security flaws for far too long, Database Center Editor Lisa Vaas writes. Click here to read more.

      For ASI to classify a vulnerability as high risk means that exploits can be almost as simple as opening a command line and establishing a connection to the database, Gonzales said.

      At the time this story went to press, ASI was planning to burn the midnight oil as it tests Oracles patches to determine their effectiveness running on various operating systems.

      And ASI continues to uncover more vulnerabilities, Gonzales said. “We discovered about 20 of these vulnerabilities, and its growing,” he said. “Every vulnerability encompasses a ton of other vulnerabilities. Were trying to nail down what packages and functions they affect. Theyre all interrelated. Developers are coming over to me every other hour, telling me theres something new.”

      /zimages/4/28571.gifClick here for more details on which products are affected by the patches.

      Oracle recommended prompt patching. “Providing customers with information and workarounds for security vulnerabilities is vital to protecting information systems,” the company said in a statement.

      “To that end, Oracle is informing customers that potential security vulnerabilities have been discovered in Oracles Database and Application Server and Enterprise Manager products. Oracle recommends that customers apply patches for these potential vulnerabilities.”

      /zimages/4/28571.gifFor insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

      The sheer number of Oracle vulnerabilities found since January, added to the fact that Oracle has jumped on Microsoft Corp.s monthly patch release bandwagon, suggest that Oracle could be facing the same type of security headaches that have plagued its rival, Gonzales suggested.

      “Its been growing,” he said. “If you look at what happened to Microsoft in the past, its in the beginning stages of whats probably going to be coming. Oracles already been forced to operationalize on a regular basis, just like Microsoft. They now have a security Web page.

      “Microsoft has an automatic way of developing bulletins. Theyre fairly open to security vulnerabilities and addressing them. Oracle will have to do the same thing. I think its the beginning of more to come. Its the first step in an evolution of how vendors should be managing this stuff.”

      /zimages/4/28571.gifClick here to listen to an archived version of eWEEK.coms recent eSeminar on protecting customer data.

      ASI will issue an update of ASAP, its live-update package for its AppDetective network-based vulnerability-assessment tool, as soon as its completed testing of the patches and found that they do in fact remedy the vulnerabilities, Gonzales said.

      The security patches are available on Oracle Technology Network and on Oracles support site, Metalink.

      /zimages/4/28571.gifCheck out eWEEK.coms Database Center at http://database.eweek.com for the latest database news, reviews and analysis.

      /zimages/4/77042.gif

      Be sure to add our eWEEK.com database news feed to your RSS newsreader or My Yahoo page

      Lisa Vaas
      Lisa Vaas
      Lisa Vaas is News Editor/Operations for eWEEK.com and also serves as editor of the Database topic center. She has focused on customer relationship management technology, IT salaries and careers, effects of the H1-B visa on the technology workforce, wireless technology, security, and, most recently, databases and the technologies that touch upon them. Her articles have appeared in eWEEK's print edition, on eWEEK.com, and in the startup IT magazine PC Connection.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.