Most Oracle database admins don't apply patches?

Around 70 percent of Oracle database professionals say they have never applied a security patch, according to database security firm Sentrigo.

In a survey of 305 Oracle professionals, Sentrigo claims the majority did not apply the Oracle patches released in Oracle Critical Patch Updates. This leaves users' databases open to compromise, according to analyst company Canalys.

When asked at various US Oracle User Group meetings last year, the Sentrigo survey found 67.5 percent of respondents said they had never applied any Oracle critical patches, and 90 percent said they had not yet applied patches from the most recent Critical Patch Update, which was released in October 2007.

Users cited concerns over downtime and compatibility with applications as reasons not to patch.

"On the face of it, these survey results look alarming," said Andy Buss, senior Canalys analyst. "Not patching can leave companies open to compromise. Companies need to get into the routine of testing and applying patches, for the sake of compliance."

Compliance issues can arise if companies are subject to regulations such as PCI DSS (Payment Card Industry Data Security Standard), where non-compliance can result in fines, or Sarbanes-Oxley, where weaknesses in security controls in systems such as Enterprise Resource Planning can lead to "consequences" for C-level officers, said Buss.

Oracle periodically releases patches in the form of Critical Patch Updates. The next Oracle Critical Patch Update is due to be released on Tuesday 15 January, and in a pre-release announcement, Oracle warned that this update will contain "27 security fixes across hundreds of Oracle products". Some of the vulnerabilities to be addressed in the Critical Patch Update affect multiple products, Oracle added.

Products affected include versions of Oracle Database, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite, Oracle Enterprise Manager Grid Control, Oracle PeopleSoft Enterprise PeopleTools and Oracle PeopleSoft Enterprise Human Capital Management. Ten of the 27 vulnerabilities to be addressed may be exploited remotely without authentication, said the pre-release announcement.

Buss said that companies should patch vulnerabilities identified by the manufacturer, list updates to work out if they need to be installed, and institute a timed procedure to test and update necessary patches.

However, there are also ways of mitigating the risk of compromise without patching, said Buss. Companies can deploy technologies that monitor data flows between database servers and hosts on the network, and inspect traffic for anomalies. Organisations should also build network architecture that doesn't allow PC traffic to go into the data centre, said Buss.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

What happens when you have 'too many cooks' while creating software: http://t.co/8ITO4zZs

SAP buys Ariba http://t.co/cQy8nVWp ^ST

Google closes Motorola Mobility deal - ZDNet Australia: http://t.co/njPFGeOB.auGoogle closes Motorola Mobility de... http://t.co/V6ygypla

by http://t.co/vmlLt4bh: SAP eyes cloud super network with Ariba buy: SAP America is looking to develop "the busi... http://t.co/9OhJ6p9V

SAP eyes cloud super network with Ariba buy http://t.co/7NL5eFce

BYOD too immature for us: Human Services http://t.co/s3x2cthG via @zdnetaustralia

Google closes Motorola Mobility deal: Google has finally closed its acquisition of Motorola Mobility, installed ... http://t.co/U2G7DO7D

The federal government has released guidelines for a community cloud to be shared by agencies http://t.co/57skHLug ^ST

Fed Govt steps up on shared cloud plan - Communications - News - ZDNet Australia | @scoopit http://t.co/s0x8e1hr

Now that Google has closed its acquisition of Motorola Mobility, what's next on the company's to do list? http://t.co/5aWbp9qe ^ML

Fed Govt steps up on shared cloud plan http://t.co/dY5uxJuh

I'm a payed up lib member who has voted Labor in the last 2 federal elections. I had the previlege of speaking to Mr Turnball 3 months ag...

32 minutes ago by spazmanaught on NBN contracts may be left alone: Turnbull

Good to see Westpac's concentrating on the real IT issues !

36 minutes ago by jeff_syd on Westpac board goes paperless with iPads

Fed Govt steps up on shared cloud plan - ZDNet Australia: The Australian Government Information... http://t.co/lIRepJnI #cloud #news #AU

by http://t.co/vmlLt4bh: Fed Govt steps up on shared cloud plan: The Federal Government has proposed advancing it... http://t.co/YO4h9UI8

Google closes Motorola Mobility deal http://t.co/BkGBmagB

Fed Govt steps up on shared cloud plan: The Federal Government has proposed advancing its shared cloud strategy ... http://t.co/Yc2QBYPx

Fed Govt steps up on shared cloud plan - ZDNet Australia: Fed Govt steps up on shared cloud planZDNet AustraliaT... http://t.co/5bb7Wz1G

BYOD: What the people think | ZDNet http://t.co/0EMHmiCg

Anonymous hacks Bureau of Justice, leaks 1.7GB of data - http://t.co/HFqI12Q9 #InfoSec

Fed Govt steps up on shared cloud plan: The Federal Government has proposed advancing its shared cloud strategy ... http://t.co/dq95elts

Fed Govt steps up on shared cloud plan: The Federal Government has proposed advancing its shared cloud strategy ... http://t.co/ReA93WL9

Consumer Reports recommends Nokia Lumia 900 for dads and grads http://t.co/LsWkcsU0

#Spotify finally goes Live in Australia http://t.co/VFP8Xq8U

"@ZDNet: SAP gets huge cloud and extended business process boost with Ariba acquisition http://t.co/Ro04GlP4" ->#SAP strengthening its cloud

RT @zdnetaustralia: The Westpac board have gone paperless using iPads and a secure, home-grown app environment: http://t.co/F1d17bvF ^LH

BYOD: What the people think http://t.co/5Mh2x0u9 via @zite #byotchat #edtech

Interesting..Who uses Twitter for job search? http://t.co/KuWVItXK @zdnetcharlie

SAP gets huge cloud and extended business process boost with Ariba acquisition: SAP is focused on global cloud g... http://t.co/75ps1wG3

Microsoft exec: Dynamics CRM, AX aims to feast Oracle, SAP switchers http://t.co/XiC912eT

#SAP wants to be the biggest cloud player by 2015... http://t.co/fLwejro7

RT @playbiggeradv: #SAP wants to be the biggest cloud player by 2015... http://t.co/fLwejro7

Handy overview of #Android 's major #security flaws: http://t.co/oiVrKSHb #mobile #infosec

The implications of NZ school Principals demanding access to student mobile devices | ZDNet http://t.co/jMSJXzpT

Google closes Motorola buy: http://t.co/9ezoLnSg

War talk dominates #AusCERT 2012 - http://t.co/WbuTt174 - #security #cyber

Nuance launches in car voice activated platform (Zack Whittaker ZDNet) http://t.co/9mFEA93c

I am not sure how this issue becomes an attack on Mr Turnbull. But I guess he is fair game. In any event I would have thought a Ddos woul...

11 hours ago by Doubt on National Botnet Network coming: Earthwave

I still use 98SE. Windows ME was an abortion in a bucket and Vista was ME without the bucket. My screen may look boring, but I jumped str...

11 hours ago by Treknology on Microsoft admits Vista was 'cheesy'

This story has been voted 10 times in the last 24 hours!

11 hours ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

12 hours ago, Lenovo ThinkPad 3G tablet (32GB)

Well I don't know what they have done with their EFTPOS machines, local one in WA Coles Express I used this morning and I normally do "ch...

12 hours ago by harryinthesoup on Coles ditches PINs in payment pilot

6.7 M last ditch attempt - interesting - The Auckland region (population 1.4 mil) has estimated to have spent less than this in total ...

15 hours ago by debsteele on Vic scraps HealthSMART system

Interesting - no mention of Win 98/ME/2000 ... which heralded Internet access for millions of users ? I thought Win 98/ME would be the mo...

16 hours ago by gouranga on Microsoft admits Vista was 'cheesy'

An Application like Good from Good Technologies does the same thing, working with the enterprise email server and is off the shelf.

16 hours ago by Helpdesk123 on Westpac board goes paperless with iPads

Never mind a "B+" version, go for "C" and put in a few extras. I'd like a high speed ADC (100Msps) but that's just me... Final size? Equ...

17 hours ago by sa_penguin on Raspberry Pi architect mulls design change

what a non-story. these thing happen all the time. is zdnet short on material?

18 hours ago by paulwrussell on Spotify launch suffers redirect bungle

4 months old phone died. Took 6 weeks, three visits to the authorised repairer (Fonebiz) to "fix it". 2nd hand untested parts used, I say...

18 hours ago by paracin on Sony Ericsson Xperia Arc S

It's easy to rubbish an old operating system long after the rest of the world has already passed judgement upon it. I would be far more i...

19 hours ago by ramnet on Microsoft admits Vista was 'cheesy'

If Vista is cheesy, Metro is an over-ripe Stilton.

19 hours ago by meski on Microsoft admits Vista was 'cheesy'

you are kidding right - what qualification do you have to make such wildy stupid statements - do you really have customers who pay you fo...

19 hours ago by rant rant rant on National Botnet Network coming: Earthwave

Exactly. There are two topics of discussion, that are co-mingled; 1) Unauthorized software was put on the company device, by an IT person...

23 hours ago by lamont on ABC's Bitcoin miner tackled in minutes

First off, Bitcoin is not a virus. Second off, the only way to generate Bitcoins, is by using a Bitcoin miner. More information on this h...

1 day ago by rizowski on ABC's Bitcoin miner tackled in minutes

When an operating system is sold it should not launch until an approved security service is purchased online with a list of approved supp...

1 day ago by Kevin Cobley on National Botnet Network coming: Earthwave

Admits? Don't fall for their marketing. Vista was beautiful. Microsoft has a history of trashing their older OSes.

1 day ago by anonymuos on Microsoft admits Vista was 'cheesy'

Gotta agree. For our Burnie, Tas. internet, we have a 1.5MB download speed adls connection through exetel using testra copper line. ADS...

1 day ago by brozza on Broadband Speedtest

Well the message certainly is clear. Never do anything because something might happen. Seriously it seems to me "Earthwave" just want to...

1 day ago by Hubert Cumberdale on National Botnet Network coming: Earthwave

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar