Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cybersecurity
    • Database

    Gartner Disses Oracle Security

    Written by

    Lisa Vaas
    Published January 25, 2006
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Close on the heels of Oracles latest critical patch update, Gartner has published an advisory warning that, given the seriousness and the ease of exploit of the flaws involved, administrators have got to get over their laissez-faire attitude toward patching.

      “Oracle has not yet experienced a mass security exploit, but this does not mean that one will never occur,” Gartners Rich Mogull wrote.

      Oracle administrators have traditionally relied on their servers being well tucked behind firewalls, in addition to Oracles good record on strong security, and have thus oftentimes been slow to patch.

      /zimages/3/28571.gifOracle users often shrug at security woes. Click here to read more.

      “Oracle databases have traditionally been located fairly deep within the enterprise,” Mogull said in an interview with eWEEK. “People are now used to, when a CPU [Critical Patch Update] comes out, to wait days to patch. With Oracle, they tend to wait longer. These systems run well, these systems dont have downtime issues, so administrators wait a bit of time before installing patches. … Its fairly well-understood in the industry they dont patch as frequently” as users of other vendors software, he said.

      Beyond that, Mogull said, patching is sometimes impossible, given lack of support for legacy Oracle versions. “Oracle doesnt support products quite as long as some other vendors out there,” he said.

      Hence, “many, many” clients are locked into older Oracle versions, since they rely on third-party applications that run on those older systems, he said.

      Regardless, the current laid-back attitude toward patching is unacceptable, Mogull said. “Critical Oracle vulnerabilities are being discovered and disclosed at an increasing rate, and exploit tools and proof-of-concept code are appearing more regularly on the Internet,” he wrote in the advisory.

      “At least on administrators side, its time to update their management practices a bit, to better prepare” for testing and patching, he said.

      This need for more nimble patching shouldnt be too onerous, given Oracles switch to a quarterly patch release, Mogull said—a circumstance that puts patching on a predictable, regular schedule.

      Next Page: Is a massive Oracle exploit inevitable?

      Page 2

      At this point, no massive Oracle exploit has ever seized headlines a la Microsofts experience with Slammer, et al. But researchers consider the event inevitable, given that some of the discovered Oracle flaws include SQL injections, which are easy to execute remotely via Web applications, Mogull said.

      A case in point is DB18, one of the 82 patches issued by Oracle in January. Security experts warn that Oracle is obfuscating the seriousness of this flaw, which would allow any user to take control of an Oracle database just by modifying a URL.

      As splashy as Slammer and its ilk are, an Oracle exploit would likely be more quiet and more lethal, given that Oracle databases and other applications run in the worlds largest enterprises and thus contain far more valuable data.

      “If we do see an exploit, well see worms quietly deploying and stealing information from systems,” Mogull said. “I want to give Oracle credit. Theyre the leader in databases because its a great product. Theyre used in some of the most trusted environments out there.”

      Oracle has long been criticized for lack of communication regarding specifics on vulnerabilities.

      /zimages/3/28571.gifOracle faces growing criticism about poor quality patches, known vulnerabilities left unpatched for too long, and poor communication about vulnerability specifics. At customers urging, its now working to turn it all around. Click here to read more.

      “Theyre years behind the industry,” Mogull said. “Theres no other way to put it. Theyre trying to pave a path for issues that were determined long ago.”

      Oracles policy toward providing specifics has long been that it doesnt want to provide a road map for hackers to exploit systems. Thus, they often patch vulnerabilities without describing what the vulnerabilities are. Both are “archaic” practices, Mogull said, that run under the assumption that the bad guys wont discover the vulnerabilities on their own.

      “Those guys are going to reverse-engineer these patches,” he said. “As well as some security researchers will release vulnerability information when they get it. But Oracle wont validate” the vulnerability information, he said.

      “They evaluate it, they determine what the risk is, and they tell you what the risk is, in terms of impact,” Mogull said. “Thats patronizing. If Im an Oracle administrator or security officer, its my job to measure risk to my organization, and I need the information to do that.”

      As it is, Oracle has been working on better communication ever since the infamous Alert 68, Oracles first multiple-patch release. When it was released, in August 2004, Next-Generation Security Software reported 10 vulnerabilities, including buffer overflow issues, PL/SQL injection, trigger abuse, character set conversion bugs and denial of service. Customers also complained of Oracles lack of communication on severity issues.

      Since then, Oracles move to faster communication can be seen in the aftermath of the malicious Voyager non-activated worm code. Even though the non-worm was the result of insecure configuration on Listener accounts and not the result of a code flaw, Oracle rushed to get information to customers regarding proper configuration.

      Still, Mogull said, he expects better from a company with such good security features. “They have some of the best security features on the market,” he said. “Theyre years ahead of their competitors. But all of that is negated because of their cruddy disclosure policies. I cant rate that product highly as a secure product. I dont care how many features you have.”

      Oracle hadnt yet responded to a request for comment by the time this story posted.

      /zimages/3/28571.gifCheck out eWEEK.coms for the latest database news, reviews and analysis.

      Lisa Vaas
      Lisa Vaas
      Lisa Vaas is News Editor/Operations for eWEEK.com and also serves as editor of the Database topic center. She has focused on customer relationship management technology, IT salaries and careers, effects of the H1-B visa on the technology workforce, wireless technology, security, and, most recently, databases and the technologies that touch upon them. Her articles have appeared in eWEEK's print edition, on eWEEK.com, and in the startup IT magazine PC Connection.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.