Oracle Leaves Databases Vulnerable, Say Researchers

  /     /     /  
Publicated : 22/11/2024   Category : security


Oracle Leaves Databases Vulnerable, Say Researchers


As SQL injection attacks and other advanced threats gain traction, researchers complain that Oracles other application efforts distract it from shoring up database security.



Is Oracle just paying lip service to database security? Some researchers within the database community think so, complaining that as the software juggernaut has grown with acquisitions, such as the blockbuster Sun deal, it hasnt maintained enough resources to securely develop database products and resolve vulnerabilities disclosed by researchers in a timely fashion.
I would say easy fixes get done pretty quickly, within three to six months, but things that are harder and need some changes in architecture or have an impact on customers where customers have to make some changes to their products, to their software that uses the databases, those things dont get done in the CPU, said Alex Rothacker, manager of Application Securitys research arm, TeamSHATTER. We have a vulnerability disclosed where basically we can brute force any users password ... we reported this two years ago and they havent fixed it yet.
Its a complaint lodged by many researchers, who say that even as Oracle publicly states it wants to work with the research community to fix database issues, it isnt putting its shoulder into the effort. The numbers show that the proportion of quarterly critical patch updates for Oracle database products has diminished considerably over the last two years.
While some might come to the conclusion that there are fewer updates because Oracles products are getting more secure, researchers say this trend has occurred simultaneously as the window between disclosure of vulnerabilities and patch releases for them has grown wider.
They respond immediately and say Thank you very much for the information and so on, but it sometimes takes more than a year to actually release a patch, said Slavik Markovich, VP and CTO of database security for McAfee. I get the feeling that they dont invest enough or have enough people working on this so it takes a long time to patch. In the meantime, too, new database products--some of them security related, even--are released with the same type of vulnerabilities that researchers have been alerting Oracle to for years.
Read the rest of this article on
Dark Reading
.
In todays uncertain and highly scrutinized financial services industry, achieving effective risk management is vital for survival. The report examines the need for enterprise risk management, the benefits of holistic data management, and ERM best practices.
Download the report now
. (Free registration required.)

Last News

▸ CryptoWall is more widespread but less lucrative than CryptoLocker. ◂
Discovered: 23/12/2024
Category: security

▸ Feds probe cyber breaches at JPMorgan, other banks. ◂
Discovered: 23/12/2024
Category: security

▸ Security Problem Growing for Dairy Queen, UPS & Retailers, Back off ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Oracle Leaves Databases Vulnerable, Say Researchers