Now that's a mess… in Oracle Bug Database Susceptible to 'Metalink Hacking' I just read about the Oracle security research firm Red Database Security GmbH that has found 42 bugs, some serious, in Oracle Corp.'s Metalink knowledge base, and determined that it's possible to search Oracle's bug database for customer e-mails, used configurations, test cases and other sensitive information in a foray similar to "Google hacking."
"Within 42 hours I was able to find 42 bugs with security potential (e.g., denial of service, SQL Injection, …)," RDS' Alexander Kornbrust said from Germany via an e-mail conversation. "I stopped after 42 bugs." He said he then reported the bugs to Oracle.
let's hope Oracle finds the time to address such issues soon and with good PR consultation because
What makes the vulnerabilities particularly disturbing, security experts say, is that Oracle has built up such a rich repository in its Metalink forum.
Comments
42 bugs in Oracle Metalink - revealing sensitive customer data
I am new to Oracle having secured a post as a DBA which I am really starting to enjoy after an eight month struggle. However I am soon to commence testing prior to an up-grade from 11i,10(8) to 11i,10(10) and I was wondering if you could forward me any useful information in relation to new features as my colleagues in my Information Management Team are pretty slow at assisting me.
I thank you for your assistance in this matter and I look forward to hearing from you.