| Oracle drops critical database server patch bundle |
|
|
|
| Written by Administrator | |
| Monday, 26 February 2007 | |
|
The January 2009 CPU includes 20 new security fixes for the company’s flagship database product lines, 4 new security fixes for the Oracle Application Server, 9 vulnerabilities in Oracle Secure Backup, 4 new security fixes for the Oracle Applications Suite, and 6 new security fixes for the PeopleSoft and JDEdwards Suite. On the Oracle Database side, here’s a breakdown of the main patches:
According to Alexander Kornbrust from Red Database Security, the most critical bug could allow any user with execute privileges on dbms_ijob (e.g. DBA or hacker/user with DBA privs) to bypass Oracle Auditing completely. This means no traces in the AUD$ and/or the operating system! All databases are affected. Risk matrix definitions, including CVSS scores for all the vulnerabilities, are included in Oracle’s advisory. * Image source: Oracle Security at Amazon.com. *source http://blogs.zdnet.com |
|
| Last Updated ( Friday, 16 January 2009 ) |
| Next > |
|---|
| PT. SAE |
| STMIK WUP |
| Bappeda Banyumas |
| PT. Telkom |
| MWN |
Feel free to get in touch with us!
Address Perum Arcawinangun Estate