Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cybersecurity
    • Database

    Oracles Quarterly Patch Plan Gets Cautious Nod

    Written by

    Lisa Vaas
    Published November 18, 2004
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      In switching to a schedule of quarterly patch rollup releases, Oracle Corp. is sparing grateful DBAs and customers from the constant patching of monthly releases, to which the company originally alluded three months ago.

      “We began talking about going to a regularly scheduled delivery model for patch delivery over the last year,” Oracle chief security officer Mary Ann Davidson said Thursday in a conference call with journalists.

      “We found that customers would prefer to get things on a schedule they can plan around that fixes multiple things, as opposed to patching on, say, a Wednesday or a Thursday, being forced to drop [other tasks], and patching under duress.”

      /zimages/4/28571.gifClick here to read about Oracles earlier decision to patch monthly.

      Duress is certainly what customers feel when facing monthly patching, according to Ian Abramson, chief technology officer at Red Sky Data Inc., in Toronto.

      “Its a good idea to decrease the frequency,” Abramson said. “[Database administrators] have enough to do now. If they put out a patch every month, theres no way theyre doing anything but installing patches,” what with testing the patch, backing up the system in question and then installing the patch, he said.

      When people speak of monthly patch releases, they are of course talking about Microsoft Corp.s patch release schedule. Whereas most agree that copying Microsofts schedule would put an undue burden on already maxed-out DBAs, some say they would encourage Oracle to copy its rival in other ways, such as picking up on the automatic patch update capability and tools built into Microsofts infrastructure.

      “Microsoft has spent a lot of time and money making the patching process easy and fast,” said Aaron Newman, database security expert, chief technology officer and co-founder of Application Security Inc., in New York.

      “With auto update and tools that make it pretty simple to roll out, you have the facility to roll a patch out to 5,000 servers. Oracle doesnt have the ability to roll out patches to 5,000 servers,” at least not easily, Newman said, given the fact that it takes four to five hours to research a patch, back up the database, test the patch and install it.

      Not everybody thinks the click-here scenario is appetizing when it comes to Oracle systems, however. “In theory I like it. … But Im not willing to trust that to a point-and-click scenario,” Abramson said. “You dont want it to be too simple so that anybody who does it may not have the knowledge to do it.

      “I would like to see Oracle simplify [patch installation], because it would be nice to just click and get updates, and part of the database installer would be that it just downloads a patch and starts the installer. … But if its just point and click, its a little too easy to install [something like Windows Service Pack 2, about which many complaints have been lodged].

      “Things go critically wrong, and your business ends up further behind than they would have been had they been a little more careful with the installation,” he said. “Its too easy to hit yes to continue when you should have hit no.”

      Next Page: No further patch details forthcoming.

      No More Details

      The patch release schedule, due to begin Jan. 18, will encompass patches for all Oracle products, including Application Server, Oracle Database, Oracle E-Business Suite, Oracle Enterprise Manager and Oracle Collaboration Suite. The patches will be available via Oracles MetaLink support site.

      Subsequent patches will be issued on April 12, July 12 and Oct. 18, with interim patches possible in the eventuality that serious, critical vulnerabilities arise, Oracle said.

      These dates were chosen to maximize customers schedules, avoiding blackout periods when customers are, for example, closing books at the end of a quarter, Davidson said.

      The database giant has no plans to increase the amount of detail it gives on patches, however, according to Davidson—an omission that some call regrettable.

      Analyst firm Gartner earlier this week issued a report in which it bemoaned Oracles refusal to provide more detail on the consequences for users if they fail to apply security patch 68. According to the research note, Oracle declined to say whether the vulnerabilities affect older, nonsupported versions. “At worst, records in every Oracle database you own could be vulnerable,” the report said.

      Davidson defended Oracles policy of keeping details close to the vest, saying that the company is walking a fine line between informing customers and giving hackers the information they need to exploit a given flaw in the wild.

      “Our position has always been to strike a balance between providing enough information so customers know what the risk is for not applying a patch, and not giving people information to crack systems,” she said.

      “Its certainly true that, as part of our ongoing discussions over the last year on moving to this patch model, we continue to talk about what is the right amount of information and what you need to decide whether you should apply the patch.

      “That is not the same level of detail that some in the more technical research community want to see, but our primary focus is serving customers,” Davidson said.

      Its true: The more technical security research community would indeed like to see more information freely shared—particularly given that hackers already possess the information, Newman said.

      “Unfortunately, all the hackers already know everything about this,” he said. “The hackers are some of the people who found these [vulnerabilities], and the hackers are the ones who reported them to Oracle, and theyre the ones already sharing exploit code on them. Theyre the ones who already have the information.”

      /zimages/4/28571.gifRead more here about security researchers calling for additional info from Oracle.

      Newman said customers have been calling specifically seeking information on whether they should install patch 68 and what the issues are concerning workarounds, for example. “They havent been able to get the information from Oracle,” Newman said.

      Gartner backs up Newman on the issue.

      “Gartner recognizes that making detailed information public could help hackers and lead to successful exploits,” Gartners note says. “However, providing details of an exploit differs from offering information about the implications of not protecting yourself against that exploit.

      “We believe that Oracle is erring by refusing to discuss how vulnerable customers are if they do not apply the patch. System administrators do not have enough information to decide what to do (for example, which servers to prioritize or which data is most vulnerable), and this could delay the implementation of patches.”

      They are two fine lines to walk: how often to send out patches, and how much information to reveal. At this point, Oracle is playing it safe on both.

      /zimages/4/28571.gifCheck out eWEEK.coms for the latest database news, reviews and analysis.

      Lisa Vaas
      Lisa Vaas
      Lisa Vaas is News Editor/Operations for eWEEK.com and also serves as editor of the Database topic center. She has focused on customer relationship management technology, IT salaries and careers, effects of the H1-B visa on the technology workforce, wireless technology, security, and, most recently, databases and the technologies that touch upon them. Her articles have appeared in eWEEK's print edition, on eWEEK.com, and in the startup IT magazine PC Connection.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.