Two-thirds of Oracle DBAs don't apply security patches
- 15 January, 2008 10:24
- Comments
Oracle issues dozens of security patches every quarter, but that doesn't mean database administrators are necessarily implementing them.
In fact, a good two-thirds of all Oracle DBAs appear not to be installing Oracle's security patches at all, no matter how critical the vulnerabilities may be, according to survey results from Sentrigo, a vendor of database security products.
The results are "surprising, and to be candid, quite frightening," said Mike Rothman, president of consulting firm Security Incite in Atlanta.
Sentrigo polled 305 Oracle database administrators from 14 Oracle user groups between August 2007 and January 2008. The company basically asked the administrators two questions: whether they had installed the latest Oracle patches, and whether they had ever installed any of Oracle's security updates.
The results, which come even as Oracle is scheduled to release its next batch of quarterly Critical Patch Updates Tuesday, showed that 206 out of the 305 surveyed said they had never applied any Oracle CPUs. Just 31 said they had installed the most recent security update from the company. In total, only one-third said they had ever installed an Oracle CPU.
In an e-mailed statement, Oracle said the company "encourages organizations [to] apply Critical Patch Updates in a timely fashion to maintain their security posture."
"Critical Patch Updates for the Oracle Database are cumulative for the patch set to which they apply, making it easier for customers to keep their systems current with the latest security patch updates," the company said.
The results support what Sentrigo has been hearing anecdotally for sometime, said Slavik Markovich, chief technology officer at Sentrigo. "Some database administrators don't even monitor for Oracle's CPUs. They don't even know when the CPUs come out," he said. "Sometimes, even if their security department tells them to deploy it, they just ignore it," he said.
There are two major reasons for the trend, Markovich said. The first and most important is that most DBAs fear the consequences of installing a patch on a running database, he said.
"To apply the CPU, you need to change the binaries of the database," he said. "You change the database behavior in some ways that may affect application performance," he said. So applying security patches to a database typically involves testing them against the applications that feed off the database, he said. "This is a very long and very hard process to do, especially if you are in enterprises with a large number of databases and applications," he said. Applying these patches means months of labor and sometimes significant downtime, both of which most companies can't afford, he said.
Some application vendors also don't certify Oracle patches to run with their applications, Markovich said. As a result, a database administrator might, for instance, be wary of installing a patch on an Oracle database that is being used by a SAP application because that might be grounds for the application vendor to refuse addressing any disruptions to the application, he said.
Another problem is that companies that want to install the most recent Oracle patches need to first ensure that they have already installed the previous patch set, Markovich said. So companies that fail to keep up with the latest patches keep falling further behind with each patch set release, he said.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Best practices for a Data Warehouse on Oracle Database 11g
- Three government scenarios for cloud printing
- Case Study: Fairbrother constructs a reliable backup platform across its remote Branch Locations
- Why Hackers have Turned to Malicious JavaScript Attacks
- A Technical Overview of the Oracle Exadata Database Machine and Exadata Storage Server
-
Customer service still dogs Telstra
-
Customer service still dogs Telstra
-
Customer service still dogs Telstra
-
Foxtel subscriber base grows
-
Obama's H-1B answer in forum may haunt him
-
Excel 2007 All-In-One Desk Reference for Dummies
-
MYOB Software for Dummies 6E Australian Edition
-
Computers for Seniors for Dummies, 2nd Edition
-
Windows 7 for Dummies®
-
Windows 7 for Seniors for Dummies®
-
Microsoft Office
-
Office 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies® Dvd+book Bundle
-
Teach Yourself Visually Windows 7












Comments
Post new comment