Newsletter:

Skip Navigation LinksHome > News > Security > Oracle plugs 122 security holes

Oracle plugs 122 security holes

By Tom Sanders
20 October 2006 09:42AM
Tags: oracle | plugs | 122 | security | holes

Database vendor flips switch on vulnerability score reporting.

Oracle has released a 'critical patch update' that plugs 122 security vulnerabilities across the company's databases, enterprise applications, developer tools and middleware. 

The vendor issues its security updates on a quarterly basis and is now using a system that assigns a severity score to its bugs on a scale of one to 10.

Oracle has also started providing additional information indicating whether a flaw can be exploited by remote attackers without any authentication credentials. The system is designed to help administrators identify the most urgent issues.

The most important security flaw was assigned a 'base score' of 7.0 and affects Oracle Application Express. The company's flagship database received a total of 22 fixes, with the most severe ranked at 4.2.

The scores are assigned using the industry standard Common Vulnerability Scoring System which is also used by Cisco Systems.

David Litchfield, a representative from Next Generation Security Software, criticised Oracle for failing to deliver its patches on all platforms. 

Patches for Oracle databases 9.2.0.6 and 10.1.0.5 will not be available until the end of this month.

Users running Oracle 10.2.0.1 on Linux on Power servers will also have to wait until the end of October, as will users running Oracle 10.2.0.2 on Windows.

"After a successful July 2006 critical patch update release, when Oracle had all the patches ready, it is disappointing to see Oracle slipping back into its old bad habits," said Litchfield.

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The AdventNet Manage-Engine Password Manager Pro provides a complete system for password management in one...
Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Unified Communications Podcast Centre

TopTopics
(6609) -  internet
(6412) -  iinet
(6387) -  copyright
(6387) -  afact
(5988) -  servers
(5988) -  mipi
(4786) -  telstra
(4478) -  broadband
(4426) -  nbn
(2896) -  internode
(2444) -  microsoft
(1881) -  network
(1461) -  data
(1367) -  google
(1340) -  software