Oracle

42 bugs in Oracle Metalink - revealing sensitive customer data

Now that's a mess… in Oracle Bug Database Susceptible to 'Metalink Hacking' I just read about the Oracle security research firm Red Database Security GmbH that has found 42 bugs, some serious, in Oracle Corp.'s Metalink knowledge base, and determined that it's possible to search Oracle's bug database for customer e-mails, used configurations, test cases and other sensitive information in a foray similar to "Google hacking."

Quote:

"Within 42 hours I was able to find 42 bugs with security potential (e.g., denial of service, SQL Injection, …)," RDS' Alexander Kornbrust said from Germany via an e-mail conversation. "I stopped after 42 bugs." He said he then reported the bugs to Oracle.

  • the bugs are not addressed by Oracle's latest security patch set
  • Oracle could not provide formal feedback to the report

let's hope Oracle finds the time to address such issues soon and with good PR consultation because

Quote:

What makes the vulnerabilities particularly disturbing, security experts say, is that Oracle has built up such a rich repository in its Metalink forum.

Average rating
(0 votes)

Comments

42 bugs in Oracle Metalink - revealing sensitive customer data

I am new to Oracle having secured a post as a DBA which I am really starting to enjoy after an eight month struggle. However I am soon to commence testing prior to an up-grade from 11i,10(8) to 11i,10(10) and I was wondering if you could forward me any useful information in relation to new features as my colleagues in my Information Management Team are pretty slow at assisting me.
I thank you for your assistance in this matter and I look forward to hearing from you.

Similar entries