Customers open to increased risks
Customers open to increased risks

Oracle under fire over 'Severity 1' bug secrecy

Gartner calls for greater openness from database giant

Robert Jaques

Oracle's refusal to release more specific information about a recently uncovered 'Severity 1' security vulnerability affecting its products leaves the firm's customers open to increased risks, Gartner has warned.

According to the analyst firm, on 9 November 2004, in a conversation with Gartner, Oracle declined to provide more detailed information about what vulnerabilities its security patch 68 is meant to fix.

Advertisement

The database giant insisted that this approach was in accordance with its standard policy.

Oracle first issued the security patch on 31 August and reissued the warning on 14 October after proof-of-concept exploit code began circulating on the internet.

The patch affects Oracle Database Server, Application Server and Enterprise Manager. Oracle has given these patches its most serious 'Severity 1' rating.

"Oracle refuses to provide more details about the consequences for users if they do not apply security patch 68," a Gartner advisory by analysts Neil MacDonald and Rich Mogull warned.

"Furthermore, Oracle has not said whether the vulnerabilities affect older, non-supported versions. At worst, records in every Oracle database you own could be vulnerable."

Gartner has acknowledged that making detailed information public could help hackers and lead to successful exploits.

However, the analyst stressed that providing details of an exploit differs from offering information about the implications of not protecting against that exploit.

"We believe that Oracle is erring by refusing to discuss how vulnerable customers are if they do not apply the patch," Gartner stated.

"System administrators do not have enough information to decide what to do (for example, which servers to prioritise or which data is most vulnerable), and this could delay the implementation of patches."

According to Oracle, an exploit against these vulnerabilities would look like a legitimate SQL*NET conversation and not depend on 'bad' or malformed SQL*NET commands that could be easily blocked.

The Gartner advisory went on to state: "If Oracle would provide more information about the nature of the vulnerability, customers might be able to proactively set up inspection safeguards, such as deep-packet inspection firewalls, intrusion prevention systems and application firewalls with SQL*NET capabilities."

Gartner advises firms using a supported version of the affected software to apply the Oracle-supplied patches immediately.

The analyst firm said that companies with older, non-supported versions of Oracle, such as 7.x or 8.0x, should consider an immediate upgrade or switch to an alternative product.

Additional protection can be gained by determining whether it is possible to set up an SQL*NET-capable deep-packet inspection firewall or intrusion prevention system to detect and shut down attacks, Gartner's advisory stated.

The report also advised Oracle customers to consider field-level encryption to protect data from unauthorised access, and to check Oracle's Metalink FAQ frequently for information on this patch.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Patches timed to suit Oracle?

Oracle shifts patch cycle

The database giant has revised its patching policy again and now intends to release a quarterly bundle of fixes

Quarterly critical patch updates

Oracle goes quarterly for critical patches

Easier configuration management for customers, claims database giant

Security

The latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Piracy, privacy and processing power set to be hot topics for V3.co.uk Summit

Have you got a burning desire to quiz experts from...

iPhone

World's first iPhone virus surfaces

Images of 80s icon Rick Astley spell trouble

Airvana HubBub

Airvana debuts 3G femtocell for offices

HubBub improves indoor network coverage for businesses

shopping key

E-commerce on brink of SaaS revolution

Figleaves founder argues platform-as-a-service vendor will emerge to shake up...

Primary Navigation