Imperva CTO questions Oracle security and testing process in latest patch update

Imperva CTO questions Oracle security and testing process in latest patch update

ID: 105217

(PresseBox) - 12 - Below is a comment from Imperva CTO, Amichai Shulman on the latest Oracle critical patch update (CPU):
Oracle Q1's CPU Release:
This is a standard patch. However, quite a large volume of patches are dedicated to the MySQL database which is a new introduction into Oracle's CPU process. Overall, there are 78 vulnerabilities which are consistent with previous releases. However, considering Oracle added MySQL to the patching process, this number seems low.
Key observations:
- There is a bottleneck in the Oracle patching process. If you were to introduce a new product, there should be more vulnerabilities overall in the CPU--but this didn't happen. Could there be obstacles in the security and testing process? While introducing MySQL into the patch process is a good thing, it emphasizes again scalability problems. With the introduction of a new product, especially when it shows 27 fixes in this CPU, you'd expect the number of overall patches in the CPU to increase. This has not happened. For example, the Oracle DB server product only shows two fixes.
- There are only two vulnerabilities in the database product. Why? Either the database server has reached an amazing maturity in terms of security or Oracle did not have enough resources to include more fixes into the process. This may be a consequence of adding the new MySQL product in the patching process. However, another factor may be that these fixes are much more critical and complex than their CVSS score suggests.
- Oracle continues to undervalue the severity of their reported vulnerabilities. For example, the vulnerability described in InfoWorld is CVE-2012-0082 only gets a 5.5 on the severity scale. As another proof point, one Solaris vulnerability (CVE-2012-0094), scores a 7.8 but is very similar to issues Oracle database server and MySQL products that scored just a 5.5.
- Other stuff: Other than that there are many fixes in HTTP based components of the Oracle product line.




What does this release tell us to expect from Oracle security in 2012?
- Severity scores will continue to be misleading. Oracle should rethink their "Partial+" ranking which artificially plays down the severity.
- Vulnerability bottleneck. They should fix this bottleneck, especially as they introduce new products and acquisitions continue. We assume the bottleneck exists due to the relative low number of vulnerabilities while the patch increases in terms of products covered. As in many organizations, it's safe to assume that Oracle has a security team separate from the engineering team that deals with the vulnerabilities and so the bottleneck most likely resides there and should be removed.
If you would like further information visit Imperva?s blog.

Unternehmensinformation / Kurzprofil:
drucken  als PDF  an Freund senden  Kickoff for safety: Bosch supplies security technology for sport stadiums in South America The New 'Odyssé II Evolution All Touch' : Cleverly incorporating interactive media and customer loyalty  at the cash desk, brought to you by AURES
Bereitgestellt von Benutzer: PresseBox
Datum: 18.01.2012 - 11:06 Uhr
Sprache: Deutsch
News-ID 105217
Anzahl Zeichen: 2985

contact information:
Town:

Redwood Shores



Kategorie:

Hazadous Materials Management



Diese Pressemitteilung wurde bisher 253 mal aufgerufen.


Die Pressemitteilung mit dem Titel:
"Imperva CTO questions Oracle security and testing process in latest patch update"
steht unter der journalistisch-redaktionellen Verantwortung von

Imperva Inc. (Nachricht senden)

Beachten Sie bitte die weiteren Informationen zum Haftungsauschluß (gemäß TMG - TeleMedianGesetz) und dem Datenschutz (gemäß der DSGVO).

Imperva Report Details Automated Web Application Attacks ...

12 - Imperva, Inc. (NYSE: IMPV), a pioneer and leader of a new category of data security solutions for high-value business data in the data center, today released its April Hacker Intelligence Report Automation of Attacks, which analyzes how and why ...

Alle Meldungen von Imperva Inc.



 

Werbung



Facebook

Sponsoren

foodir.org The food directory für Deutschland
Informationen für Feinsnacker finden Sie hier.

Firmenverzeichniss

Firmen die firmenpresse für ihre Pressearbeit erfolgreich nutzen
1 2 3 4 5 6 7 8 9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z