Home > Oracle Databases Go Unpatched, Survey Finds

News

Oracle Databases Go Unpatched, Survey Finds

1/17/2008

Database administrators using Oracle Database products haven't been applying Critical Patch Updates, according to survey results described by Sentrigo Inc., which is in the business of providing database security software.

Oracle typically releases its Critical Patch Updates on a quarterly basis, but these patches apparently are too much of a hassle to apply.

Sentrigo has had informal discussions with IT personnel on the matter, apart from the survey, according to Rani Osnat, Sentrigo's vice president of marketing. The reluctance to patch may stem from all of the testing and downtime that needs to happen before applying Oracle Critical Patch Updates.

"In the case of smaller companies, the DBAs simply don't have time to do it," Osnat said. "In the larger companies, you may have thousands of databases and you literally need to cycle through them to schedule downtime for all of them."

Woburn, Mass.-based Sentrigo collected the responses of 305 Oracle Users Group members in a survey that was conducted from August 2007 to January 2008. Responses were gathered across the various cities where Oracle Users Group meetings were held.

The survey found that only 10 percent (31 people) of the total number of respondents said that they had installed the latest Oracle Critical Patch Updates.

Moreover, 67.5 percent of respondents had never applied any Oracle Critical Patch Updates, according to an announcement issued by Sentrigo.

Sentrigo offers a kind of stop-gap measure to this dilemma. The company's Hedgehog solution uses a technology that Osnat calls "virtual patching."

"The idea of virtual patching is that you have a security layer that monitors the database and all transactions and looks for activities that target vulnerabilities," Osnat explained. "It looks for exploits and issues an alert. The benefit is that it doesn't require any downtime."

Virtual patching is a warning system, and it doesn't solve the root problem. A patch is still needed, eventually.

"We don't recommend it as a substitute for real patching," Osnat said. "On the other hand, most people don't do patching, so this allows them to fill in the gaps in terms of security."

Oracle's last quarterly Critical Patch Update, dated January 2008, addressed 26 new fixes across Oracle Database products.

Osnat explained that many of the vulnerabilities that have been found in Oracle Database have typically allowed SQL injection attacks. It's a method of using the main door of the SQL engine to execute commands, and these commands are then used for privilege escalation. The less severe attacks allow one to gain DBA access privileges via a login and password, but the more severe ones let anyone gain those privileges, he said.

Sentrigo's dismal survey results have an explanation, according to Osnat.

"Database security is not a major priority among IT security folks," he said. "Mostly, we think it's because of their lack of knowledge about databases and what kind of risk database vulnerabilities pose. Most IT security people are more familiar with network security or operating systems -- not so much about databases."



Recommended Reading
  • College of Southern Nevada Implementing Angel To Run Online Courses

    The College of Southern Nevada (CSN), a community college in Las Vegas with 41,000 students, has adopted the Angel Learning Management Suite (LMS) to support its online course offerings. In Spring 2008 CSN began evaluating alternatives to WebCT, which it currently runs, and made the decision to adopt Angel in the fall. In January 2009, CSN's 865 sections of online enrollment will be delivered using the Angel LMS.

  • Toshiba Brings DisplayLink to Docking Station

    Toshiba has introduced a new USB docking station that incorporates DisplayLink--a technology that allows computers to connect to projectors and other types of displays through USB 2.0.

  • Mitsubishi Ships SXGA+ Projector with DICOM Simulation

    Mitsubishi has begun shipping a new LCD-based SXGA+ projector aimed at higher education, specifically medical schools. The new MH2850U, according to Mitsubishi, is "specially engineered for projecting DICOM simulation images for use in medical education and training."

  • First Look: Komodo IDE 5.0

    Last month, ActiveState released Komodo IDE 5.0, the company's latest integrated development environment (IDE). Komodo supports multiple programming and markup languages, including HTML, JavaScript, PHP, Perl, Java, Python, C++ and more. It does not support some .NET languages at present, such as ASP/ASP.NET, C# and VB.NET.

  • IBM Offers Cloud Computing Help

    IBM last week announced consulting services specifically designed to help organizations assess their options in using cloud computing technology. "Cloud computing" is a much argued term, but it typically refers to solutions delivered over the Internet, rather than via customer premises-installed software.

  • Hollins U Chooses Omnilert for Emergency Notification Ahead of VA Deadline

    Hollins University, among other higher ed institutions in Virginia, has implemented Omnilert's e2Campus emergency notification system (ENS) just ahead of a state-mandated deadline requiring them at every public institution of higher education by Jan. 1. Hollins itself isn't a public campus, but wished to implement an ENS before the end of the year, the school said in a company statement.