Imperva CTO's perspective on the July 2011 Oracle CPU

Imperva CTO's perspective on the July 2011 Oracle CPU

ID: 31277

(PresseBox) - 11 - "The July 2011 Oracle vulnerability announcement contains fixes for 78 vulnerabilities in total, 16 of which are in the database server product.
I have three observations: First, this is a good-sized set of patches for both general Oracle products and in particular the database. Here, you can see the Oracle vulnerability volume per CPU.
Second, for this release, and historically, the security scoring clearly doesn't always reflect the true operational risk. For example, CVE-2011-2253 is rated as a 7.1 on the severity scale (CVSS score). However, it requires privileged SYSDBA to abuse this vulnerability which would place this problem much lower on most security professional's priority list. Consequently, this should be scored lower. By contrast, CVE-2011-0835 and CVE-2011-0880, allow you to take over the entire database with just a valid set of credentials yet scores much lower at 6.5. Unfortunately, given the pervasiveness of the Oracle database, mislabelling the security impact of vulnerabilities can adversely affect the risk management process.
Third, with JRockit and Oracle Secure Backup, we see serious security problems with these products-again. These products are notorious for producing severe vulnerabilities. In this case, CVE-2011-0873 and CVE-2011-2261, each received a CVSS score of 10. The lesson? Oracle should take a closer look at the security of these products as their poor track record may indicate a deeper, systemic security problem."



Unternehmensinformation / Kurzprofil:
Bereitgestellt von Benutzer: PresseBox
Datum: 20.07.2011 - 14:12 Uhr
Sprache: Deutsch
News-ID 31277
Anzahl Zeichen: 0

contact information:
Town:

Redwood Shores



Kategorie:

Business News



Diese Pressemitteilung wurde bisher 410 mal aufgerufen.


Die Pressemitteilung mit dem Titel:
"Imperva CTO's perspective on the July 2011 Oracle CPU"
steht unter der journalistisch-redaktionellen Verantwortung von

Imperva Inc. (Nachricht senden)

Beachten Sie bitte die weiteren Informationen zum Haftungsauschluß (gemäß TMG - TeleMedianGesetz) und dem Datenschutz (gemäß der DSGVO).

Imperva Report Details Automated Web Application Attacks ...

12 - Imperva, Inc. (NYSE: IMPV), a pioneer and leader of a new category of data security solutions for high-value business data in the data center, today released its April Hacker Intelligence Report Automation of Attacks, which analyzes how and why ...

Alle Meldungen von Imperva Inc.



 

Werbung



Sponsoren

foodir.org The food directory für Deutschland
News zu Snacks finden Sie auf Snackeo.
Informationen für Feinsnacker finden Sie hier.

Firmenverzeichniss

Firmen die firmenpresse für ihre Pressearbeit erfolgreich nutzen
1 2 3 4 5 6 7 8 9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z