You are here: silicon.com > Software > Security Strategy

Security Strategy

Gartner: Don't let security slip over Oracle apps

Be "more aggressive"...

Tags: security, oracle, gartner

By Munir Kotadia

Published: 25 January 2006 08:30 GMT

Analyst group Gartner has warned IT managers to be "more aggressive" when protecting their Oracle applications because, according to Gartner, they are not getting enough help from the database giant.

Gartner published an advisory on its website just days after Oracle's latest quarterly patch cycle, which included a total of 103 fixes with 37 related to flaws in the company's database products. Some of the flaws carry Oracle's most serious rating, which means they're easy to exploit and an attack can have a wide impact.

According to the advisory, which was posted on Monday by Gartner analyst Rich Mogull, "the range and seriousness of the vulnerabilities patched in this update cause us great concern... Oracle has not yet experienced a mass security exploit but this does not mean that one will never occur".

Mogull said that because Oracle has historically been seen as having very strong security and many of Oracle's products are located "deep within the enterprise", IT managers often neglect their patching duties.

Mogull, who advises managers to pay more attention to securing their Oracle applications, added: "Moreover, patching is sometimes impossible, due to ties to legacy versions that Oracle no longer supports. These practices are no longer acceptable."

He said IT managers should:

  • Immediately shield these systems as well as possible, using firewalls, intrusion prevention systems and other technologies.

  • Apply available patches as rapidly as possible.

  • Use alternative security tools, such as activity-monitoring technologies, to detect unusual activity.

  • Put pressure on Oracle to change its security management practices.

Oracle did not immediately respond to requests for comment.

In response to the Oracle patch release, Symantec raised its ThreatCon global threat index to Level 2, which means an outbreak is expected. It typically does that after a patch release because malicious hackers might use the fixes as a blueprint for attacks.

CNET News.com's Joris Evers contributed to this report

Munir Kotadia writes for ZDNet Australia

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Helpdesk Support Analyst, MS, IIS, LAMP, Unix, Digital Media

Required Skills: - Managing Helpdesk and all incident requests - Supporting Development teams - Windows server 2003/2008 - IIS - Unix/Linux Desirable ...

Technical Analyst - SMS, SCCM, WSUS - Patch & Release

Role - SMS / SCCM Technical Specialist / Analyst Location - Hatfield, Hertfordshire Salary - 23-37k basic + benefits Microsoft SMS / SCCM Technical ...

SAN Storage Specialist

Review security policies to determine system adherence to the latest policies and practices> Include all relevant patches and hot fixes in the latest ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: