« Microsoft SQL Server Upgrade Woes: 2005 to 2008 | Main | The Patching Nightmare »
Attacks on Oracle Databases Get Even Simpler
By Eric Gross | July 24, 2009
According to this article, an open source tool, Metasploit, is getting new functionality specifically created to infiltrate an Oracle DBMS environment. True, the database version being attacked in the upcoming demo is antiquated (10g rather than 10gR2 or even 11g) but this goes to show that it is critical for Oracle databases to be patched regularly, either with a CPU or the new PSU.
Even if your databases sit inside of a trusted firewall, there is always the risk of an internal threat. Protect your important data by applying patches quickly upon release by the vendor. Of course, each patch brings with it the chance of instability in your environment so test it in staging environments before rolling out into production.
Topics: 10gR2, 11g, Patches, Security
