All the latest UK technology news, reviews and analysis

Gartner slams Oracle security processes

by Robert Jaques

26 Jan 2006

Be the first to comment

  • Tweet this
Oracle
Range and seriousness of Oracle vulnerabilities is a cause for 'great concern'

Gartner has warned that recently uncovered critical Oracle vulnerabilities mean that the firm's software "can no longer be considered a bastion of security".

As a result the analyst firm urges Oracle database and application managers to begin protecting and maintaining Oracle systems more aggressively.

The warning comes after Oracle released its critical patch update on 17 January which included patches for 82 vulnerabilities across multiple product lines. 

These included all currently supported Oracle databases, Oracle Application Server, Enterprise Manager, Collaboration Suite, E-Business Suite, PeopleSoft applications and JD Edwards applications.

Rich Mogull, research vice president at Gartner, said that, although Oracle's quarterly patch programme enables system administrators to plan and schedule Oracle maintenance, the range and seriousness of the vulnerabilities patched in the latest update was a cause for "great concern".

"The database products alone included 37 vulnerabilities, many rated as easily exploitable and some potentially allowing remote database access," he said.

"Oracle has not yet experienced a mass security exploit, but this does not mean that one will never occur.

"Many Oracle administrators rely on a combination of the company's historically strong security and the fact that Oracle applications and databases are typically located deep within the enterprise, and so neglect to patch their systems regularly.

"Moreover, patching is sometimes impossible due to ties to legacy versions that Oracle no longer supports."

Mogull went on to warn that such complacency is "no longer acceptable" because critical Oracle vulnerabilities are being discovered and disclosed at an increasing rate, and exploit tools and proof-of-concept code are appearing more regularly on the internet.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

25%

1%

11%

63%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Helpdesk/Service Analyst x3

Helpdesk/Service Analyst x 3 3 Month Contract...

2nd/3rd line Technical support EMEA (FRENCH SPEAKING)

French Technical support Specialist (2/3rd Line) CCNA...

ECM Project Manager - CMS, Document Management, Web 2.0

ECM Project Manager - CMS, "Document Management", Web...

PRESALES CONSULTANT/TECHNICAL CONSULTANT (CCNA, MCITP)

Skills - Presales, Consultant / Consultancy, Technical...

To send to more than one email address, simply separate each address with a comma.