Home > Oracle Databases Go Unpatched, Survey Finds

News

Oracle Databases Go Unpatched, Survey Finds

1/17/2008

Database administrators using Oracle Database products haven't been applying Critical Patch Updates, according to survey results described by Sentrigo Inc., which is in the business of providing database security software.

Oracle typically releases its Critical Patch Updates on a quarterly basis, but these patches apparently are too much of a hassle to apply.

Sentrigo has had informal discussions with IT personnel on the matter, apart from the survey, according to Rani Osnat, Sentrigo's vice president of marketing. The reluctance to patch may stem from all of the testing and downtime that needs to happen before applying Oracle Critical Patch Updates.

"In the case of smaller companies, the DBAs simply don't have time to do it," Osnat said. "In the larger companies, you may have thousands of databases and you literally need to cycle through them to schedule downtime for all of them."

Woburn, Mass.-based Sentrigo collected the responses of 305 Oracle Users Group members in a survey that was conducted from August 2007 to January 2008. Responses were gathered across the various cities where Oracle Users Group meetings were held.

The survey found that only 10 percent (31 people) of the total number of respondents said that they had installed the latest Oracle Critical Patch Updates.

Moreover, 67.5 percent of respondents had never applied any Oracle Critical Patch Updates, according to an announcement issued by Sentrigo.

Sentrigo offers a kind of stop-gap measure to this dilemma. The company's Hedgehog solution uses a technology that Osnat calls "virtual patching."

"The idea of virtual patching is that you have a security layer that monitors the database and all transactions and looks for activities that target vulnerabilities," Osnat explained. "It looks for exploits and issues an alert. The benefit is that it doesn't require any downtime."

Virtual patching is a warning system, and it doesn't solve the root problem. A patch is still needed, eventually.

"We don't recommend it as a substitute for real patching," Osnat said. "On the other hand, most people don't do patching, so this allows them to fill in the gaps in terms of security."

Oracle's last quarterly Critical Patch Update, dated January 2008, addressed 26 new fixes across Oracle Database products.

Osnat explained that many of the vulnerabilities that have been found in Oracle Database have typically allowed SQL injection attacks. It's a method of using the main door of the SQL engine to execute commands, and these commands are then used for privilege escalation. The less severe attacks allow one to gain DBA access privileges via a login and password, but the more severe ones let anyone gain those privileges, he said.

Sentrigo's dismal survey results have an explanation, according to Osnat.

"Database security is not a major priority among IT security folks," he said. "Mostly, we think it's because of their lack of knowledge about databases and what kind of risk database vulnerabilities pose. Most IT security people are more familiar with network security or operating systems -- not so much about databases."



Recommended Reading
  • Microsoft Unveils Exchange and SharePoint as Services

    Microsoft exec Stephen Elop on Monday announced two hosted solutions from Microsoft--Exchange Online and SharePoint Online--which are now available to organizations of all sizes in the United States. The software, paid for by annual subscriptions, is hosted on Microsoft's servers and supported by Microsoft's channel partners.

  • 6 Ways Not To Become Rote Using Instructional Technology

    There are, in my experience, six strategies to consider with any use of technology that will guard against rote use of technology and facilitate critical analysis of teaching and learning effectiveness. In this article, I'll share with you the checklist I work with and encourage others to work with in learning about and using new technology.

  • Bringing Student Web "Stuff" to Campus Enterprise Systems

    How can an institution incorporate Web 2.0 learning opportunities for students, and evidence of learning from those opportunities, into existing campus technologies and processes? PlugJam is providing part of the answer.

  • Delta iTunes U Helps Meet Student Expectations for Web 2.0 Apps

    As part of a strategy to meet students' expectations to experience interactive Web 2.0 applications in their learning environments, Delta College in Michigan launched an online Delta iTunes U site this fall.

  • Tipping Point for "Content"--Dynamic Interaction, Not Static Stuff

    The word "content," as used in education, is troublesome for many educators today who see education as a constructivist process, an interaction between knower and learner, and as a student-centered activity.

  • Penn State Pilots Proctored Online Testing System from Kryterion

    The Pennsylvania State University's World Campus and Kryterion have gone public with results of a pilot in which students completed proctored exams online using Webassessor Online Secured Testing. The technology is intended to deliver tests without the need for an in-room proctor present.