Contact
QR code for the current URL

Story Box-ID: 436619

Imperva Inc. 3400 Bridge Parkway, Suite 101 94065 Redwood Shores, CA, United States http://www.imperva.com
Contact Ms Claire Hojem +44 20 7183 2841
Company logo of Imperva Inc.
Imperva Inc.

Imperva CTO's perspective on the July 2011 Oracle CPU

(PresseBox) (Redwood Shores, CA, )
"The July 2011 Oracle vulnerability announcement contains fixes for 78 vulnerabilities in total, 16 of which are in the database server product.
I have three observations: First, this is a good-sized set of patches for both general Oracle products and in particular the database. Here, you can see the Oracle vulnerability volume per CPU.

Second, for this release, and historically, the security scoring clearly doesn't always reflect the true operational risk. For example, CVE-2011-2253 is rated as a 7.1 on the severity scale (CVSS score). However, it requires privileged SYSDBA to abuse this vulnerability which would place this problem much lower on most security professional's priority list. Consequently, this should be scored lower. By contrast, CVE-2011-0835 and CVE-2011-0880, allow you to take over the entire database with just a valid set of credentials yet scores much lower at 6.5. Unfortunately, given the pervasiveness of the Oracle database, mislabelling the security impact of vulnerabilities can adversely affect the risk management process.

Third, with JRockit and Oracle Secure Backup, we see serious security problems with these products-again. These products are notorious for producing severe vulnerabilities. In this case, CVE-2011-0873 and CVE-2011-2261, each received a CVSS score of 10. The lesson? Oracle should take a closer look at the security of these products as their poor track record may indicate a deeper, systemic security problem."
The publisher indicated in each case (see company info by clicking on image/title or company info in the right-hand column) is solely responsible for the stories above, the event or job offer shown and for the image and audio material displayed. As a rule, the publisher is also the author of the texts and the attached image, audio and information material. The use of information published here is generally free of charge for personal information and editorial processing. Please clarify any copyright issues with the stated publisher before further use. In case of publication, please send a specimen copy to service@pressebox.de.
Important note:

Systematic data storage as well as the use of even parts of this database are only permitted with the written consent of unn | UNITED NEWS NETWORK GmbH.

unn | UNITED NEWS NETWORK GmbH 2002ā€“2024, All rights reserved

The publisher indicated in each case (see company info by clicking on image/title or company info in the right-hand column) is solely responsible for the stories above, the event or job offer shown and for the image and audio material displayed. As a rule, the publisher is also the author of the texts and the attached image, audio and information material. The use of information published here is generally free of charge for personal information and editorial processing. Please clarify any copyright issues with the stated publisher before further use. In case of publication, please send a specimen copy to service@pressebox.de.