Everything Has Changed
See how Intel developed the cure for deskside help visits in this video directed by Christopher Guest of Spinal Tap fame. Click here.
 
Cross-client Centrino® and  Core™2 processor with vPro™ Processor Technology Technical White Paper
A deeper technical dive on how vPro usage models work on both desktop and notebook PCs. Click here.
 
Intel® vPro Technology ROI Estimator
Intel® Core2™ Duo and Centrino® with vPro™ Processor technology cross-client ROI estimator. Click here.
 
WiPro Intel® Centrino® Pro with vPro™ Processor Technology
The Benefits of Intel® Centrino® Pro Processor Technology in the Enterprise. Click here.
 
Workstations Products Platforms Brief
Intel’s family of workstation platforms gives you the tools to move from serial to parallel workflows and enables you to iterate through alternatives faster and innovate more. Click here.
 
Itanium Solutions
Learn how Itanium®-based solutions are changing the way enterprises do business. Click here.


Select a newsletter and click Join to sign up!
Internet Daily
InternetNews

Business Report

Boston News
DC News
NY News
SiliconValley News




eKit: Rational Build Forge Express. Access valuable resources to help you increase staff productivity, compress development cycles and deliver better software, fast.





Oracle's 65 Flaw Update

That's a lot of flaws in one update, but it's not a record breaker.

July 19, 2006
By Sean Michael Kerner: More stories by this author:

Oracle's July Critical Patch Update (CPU) is now out with fixes for a whopping 65 bugs.

Security firm Secunia rated the aggregate of the vulnerabilities "highly critical."

The July patch haul is a significant increase over the 36 flaws that Oracle's last quarterly update in April repaired. But it is fewer than the 82 flaws for January.

The July CPU, like its predecessors, covers a laundry list of Oracle software, including:

  • JD Edwards EnterpriseOne 8.x;
  • JD Edwards OneWorld 8.x;
  • Oracle Application Server 10g;
  • Oracle Collaboration Suite 10.x;
  • Oracle Database 10g;
  • Oracle Database 8.x
  • Oracle E-Business Suite 11i;
  • Oracle Enterprise Manager 10.x;
  • Oracle PeopleSoft Enterprise Tools 8.x;
  • Oracle Pharmaceutical Applications 4.x;
  • Oracle Workflow 11.x;
  • Oracle9i Application Server;
  • Oracle9i Collaboration Suite;
  • Oracle9i Database Enterprise Edition;
  • Database Standard Edition and Oracle9i Developer Suite.

    Ron Ben-Natan, CTO of database security and compliance company Guardium, commented that more than 75 percent of the vulnerabilities addressed in the July Critical Patch Update could have impact database server availability, compared with less than 30 percent of the vulnerabilities disclosed in April.

    According to Guardium's analysis of the July CPU, Oracle Net, which is sometimes referred to as Net 8/9 or SQL*Net), RPC (remote procedure calls)(define) and the Oracle Call Inteface (OCI) represent the greatest share of patched vulnerabilities.

    In Secunia's analysis, some of the flaws in the July CPU could potentially be targeted for SQL injection attacks or compromise a vulnerable system. Other flaws Secunia noted as "unknown impact."

    Guardium's analysis paints a less ominous picture.

    "The silver lining with these vulnerabilities is that most affect only data availability and integrity, not confidentiality." Ben-Natan said. "Still, companies need to be aggressive in updating their software, as skilled hackers can quickly compromise un-patched database servers."

    Oracle is likely to only issue one more patch update before the end of 2006 in keeping with its current quarterly patch update cycle.






  • Security Archives | 7 Day InternetNews Summary | Contact Sean Michael Kerner | Back to top

    Add internetnews.com
    to your browser search box.

    IE 7 | Firefox 2.0 | Firefox 1.5.x
    Receive news
    via our XML/RSS:
    feed

    More InternetNews.com