<?xml version="1.0" ?>
<?xml-stylesheet href="" type="text/css"?>

<Channel xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
         xmlns:dc="http://purl.org/dc/elements/1.1/"
         xmlns:dcterms="http://purl.org/dc/terms/"
         xmlns="http://purl.org/net/rss1.1#"
         xmlns:p="http://purl.org/net/rss1.1/payload#"
         rdf:about="http://www.integrigy.com/oracle-security-blog">

    <title>Oracle Security Blog</title>
    <link>http://www.integrigy.com/oracle-security-blog</link>

    <description>A weblog about Oracle Security, especially the Oracle E-Business Suite 11i and the Oracle Database, written by Integrigy's Chief Technology Officer Stephen Kost</description>

    <image rdf:parseType="Resource">
        <title>Oracle Security Blog</title>
        <url>http://www.integrigy.com/favicon.ico</url>
    </image>

    <items rdf:parseType="Collection">
        
        <item rdf:about="http://www.integrigy.com/oracle-security-blog/archive/2010/07/28/webinar-oracle-cpu-july-2010-database">
            <title>Upcoming Webinar: Oracle Critical Patch Update July 2010 Database Impact</title>
            <link>http://www.integrigy.com/oracle-security-blog/archive/2010/07/28/webinar-oracle-cpu-july-2010-database</link>
            
            <p:payload xmlns="http://www.w3.org/1999/xhtml"
                       rdf:parseType="Literal"><a href="https://www1.gotomeeting.com/register/654670040"><span style="font-weight: bold;">Oracle July 2010 CPU - Oracle Database Impact</span></a><br /><span style="font-weight: bold;">Thursday, July 29, 2:00pm - 3:00pm EDT</span><br /><br />Every  quarter, Oracle releases a Critical Patch Update (CPU) that fixes a  number of security vulnerabilities in the Oracle Database.  This  quarterly eLearning session will focus on the July 2010 CPU and the  impact on the Oracle Database.  The topics will include:<br />
<ul>
    <li>A review of the security vulnerabilities fixed in this CPU,</li>
    <li>An analysis of the required CPU patches,</li>
    <li>A discussion of patching including CPUs vs. PSUs.</li>
</ul>
<br />Example vulnerabilities will be demonstrated in order to show how easy it is exploit many of the fixed security bugs.<br /><br />Click <a href="https://www1.gotomeeting.com/register/654670040">here</a> to register for this webinar.</p:payload>
            <dc:date>2010-07-28T14:09:11-05:00</dc:date>
            <dcterms:modified>2010-07-28T14:09:11-05:00</dcterms:modified>
            <dc:creator>Stephen Kost</dc:creator>
            
            
            <dc:subject>Oracle Database</dc:subject>
            
            
            <dc:subject>Oracle Critical Patch Update</dc:subject>
            
        </item>
        
        
        <item rdf:about="http://www.integrigy.com/oracle-security-blog/archive/2010/07/11/cpu-july-2010-prerelease">
            <title>Oracle Critical Patch Update July 2010 Pre-Release Analysis</title>
            <link>http://www.integrigy.com/oracle-security-blog/archive/2010/07/11/cpu-july-2010-prerelease</link>
            
            <p:payload xmlns="http://www.w3.org/1999/xhtml"
                       rdf:parseType="Literal">Here is a brief analysis of the <span class="link-external"><a href="http://www.oracle.com/technology/deploy/security/alerts.htm">pre-release  announcement</a></span> for the upcoming July 2010 Oracle Critical  Patch Update (CPU) -<br />
<ul>
    <li>Overall, 38 Oracle security vulnerabilities are fixed in this CPU,  which is a below average number but well within the range of previous  CPUs (Apr-10=31, Jan-10=24, Oct-09=38, Jul-09=30, Apr-09=43, Jan-09=41, Oct-08=36, Jul-08=45,  Apr-08=41, Jan-08=26, Oct-07=51, Jul-07=45, Apr-07=36, Jan-07=51,  Oct-06=101, Jul-06=62, Apr-06=34, Jan-06=80).&nbsp; These numbers have been normalized for Oracle products and excludes any Sun products.<br /></li>
    <li>The Oracle product and vulnerability mix appears to be similar to  previous CPUs.&nbsp; All <span style="font-weight: bold; text-decoration: underline;">CPU supported</span> Oracle Database and Oracle E-Business Suite versions are included.&nbsp; The list of  supported versions is getting very short and should be carefully  reviewed to determine if version upgrades are required prior to applying  the CPU security patches -</li>
    <ul>
        <ul>
            <ul>
                <li>Database = 9.2.0.8, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 for major platforms<br /></li>
                <li>Application Server = 10.1.2.3.0</li>
                <li>E-Business Suite = 11.5.10.x, 12.0.x, and 12.1.x<br /></li>
            </ul>
        </ul>
    </ul>
    <li><span style="font-weight: bold;">The highlight of this CPU is 4 of 6 Oracle Database security vulnerabilities are  remotely exploitable without authentication</span>.&nbsp; It is rare to have a single remotely  exploitable without authentication vulnerability in the database.&nbsp; Most  likely these 4 vulnerabilities are in the Listener, Net Foundation Layer, Network Layer, and/or APEX Application  Builder.&nbsp; If the remotely exploitable  vulnerabilities are in the Listener component, then this could only be a denial of service vulnerabilities. </li>
    <li>There are no major version support changes in for this CPU.</li>
    <li>Integrigy will be presenting more information on this CPU in the following webinars: (1) <a href="https://www1.gotomeeting.com/register/155159936">Oracle July 2010 CPU E-Business Suite Impact Webinar</a> Thursday, July 22, 2pm ET and (2) <a href="https://www1.gotomeeting.com/register/654670040">Oracle July 2010 CPU Oracle Database Impact Webinar</a> Thursday, July 29, 2pm ET. </li>
</ul>
<br /> <span style="font-weight: bold; text-decoration: underline;">Oracle  Database</span><br />
<ul>
    <li>There are 6 database vulnerabilities and four are remotely  exploitable without authentication.<br /></li>
    <li>Since at least one database vulnerability has a <a href="http://www.integrigy.com/oracle-security-blog/archive/2006/10/27/oracle-cvss">CVSS</a>  2.0 metric of 7.8 (practical maximum for a database vulnerability), this is a fairly important CPU.&nbsp; Most likely, any database account, even a lowly privileged account, will be able to gain full-control of the database by exploiting the vulnerability.<br /></li>
</ul>
<span style="font-weight: bold; text-decoration: underline;">Oracle  Application Server</span><br />
<ul>
    <li>There are seven new Oracle Application Server vulnerabilities, five of which are remotely exploitable without authentication.&nbsp; For Oracle Application Server implementations, there is only one vulnerability in the Application Server Control.&nbsp; Usually, vulnerabilities in the control utilities are only locally exploitable and require a local operating system account to exploit.</li>
</ul>
<br /><span style="font-weight: bold; text-decoration: underline;">Oracle  E-Business Suite 11i and R12</span>
<ul>
    <li>There are 7 new Oracle E-Business Suite 11i and R12  vulnerabilities, five of which are remotely exploitable without  authentication.</li>
    <li>The vulnerabilities are in the Oracle Advanced Product Catalog, Oracle Applications Framework (OAF), Oracle Applications Manager, and Oracle Knowledge Management.&nbsp; Of most interest will be the vulnerabilities in the Oracle Applications Framework (OAF) and these might exploitable in externally accessible web pages.</li>
</ul>
<br /><span style="font-weight: bold; text-decoration: underline;">Planning  Impact</span><br />
<ul>
    <li>We anticipate the criticality of this quarter's CPU will be in-line with previous  CPUs.&nbsp; The only exception may be if the remotely exploitable Oracle Database vulnerabilities are more significant than previous vulnerabilities in the networking components.<br /></li>
    <li>As with all previous CPUs, this quarter's security patches  should be deemed critical and you should adhere to the established  procedures and timing used for previous CPUs.</li>
    <li>Oracle E-Business Suite customers with externally facing implementations should carefully review the remotely exploitable vulnerabilities in the Oracle Applications Framework to determine if these pages are blocked by the URL firewall.&nbsp; If any of the vulnerable web pages are externally accessible, customers should look to immediately patch these environments.</li>
</ul></p:payload>
            <dc:date>2010-07-11T22:11:02-05:00</dc:date>
            <dcterms:modified>2010-07-11T22:12:11-05:00</dcterms:modified>
            <dc:creator>Stephen Kost</dc:creator>
            
            
            <dc:subject>Oracle Database</dc:subject>
            
            
            <dc:subject>Oracle Critical Patch Update</dc:subject>
            
            
            <dc:subject>Oracle E-Business Suite</dc:subject>
            
        </item>
        
        
        <item rdf:about="http://www.integrigy.com/oracle-security-blog/archive/2010/07/09/webinar-oracle-cpu-july-2010">
            <title>Upcoming Webinars: Oracle Critical Patch Update July 2010</title>
            <link>http://www.integrigy.com/oracle-security-blog/archive/2010/07/09/webinar-oracle-cpu-july-2010</link>
            
            <p:payload xmlns="http://www.w3.org/1999/xhtml"
                       rdf:parseType="Literal">Integrigy's CTO, Stephen Kost, will be presenting a series of webinars on Oracle's Critical Patch Update for July 2010.<br /><br /><a href="https://www1.gotomeeting.com/register/155159936"><span style="font-weight: bold;">Oracle July 2010 CPU - Oracle E-business Suite Impact</span></a><br /><span style="font-weight: bold;">Thursday, July 22, 2:00pm - 3:00pm EDT</span><br /><br />This quarterly eLearning session will focus on the July 2010 CPU and the impact on E-Business Suite environments.<br /><br />Topics will include;<br />
<ul>
    <li>a review of the security vulnerabilities fixed in the CPU,</li>
    <li>an analysis of the required CPU patches,</li>
    <li>a discussion of a high-level patch strategy.</li>
</ul>
<br />Example vulnerabilities will be demonstrated in order to show how easy it is exploit many of the fixed security bugs.<br /><br />Click <a href="https://www1.gotomeeting.com/register/155159936">here</a> to register for the Oracle E-Business Suite webinar.<br /><br /><a href="https://www1.gotomeeting.com/register/654670040"><br /><span style="font-weight: bold;">Oracle July 2010 CPU - Oracle Database Impact</span></a><br /><span style="font-weight: bold;">Thursday, July 29, 2:00pm - 3:00pm EDT</span><br /><br />Every quarter, Oracle releases a Critical Patch Update (CPU) that fixes a number of security vulnerabilities in the Oracle Database.  This quarterly eLearning session will focus on the July 2010 CPU and the impact on the Oracle Database.  The topics will include:<br />
<ul>
    <li>A review of the security vulnerabilities fixed in this CPU,</li>
    <li>An analysis of the required CPU patches,</li>
    <li>A discussion of patching including CPUs vs. PSUs.</li>
</ul>
<br />Example vulnerabilities will be demonstrated in order to show how easy it is exploit many of the fixed security bugs.<br /><br />Click <a href="https://www1.gotomeeting.com/register/654670040">here</a> to register for the Oracle Database webinar.<br /><span style="font-weight: bold;"><br /></span></p:payload>
            <dc:date>2010-07-09T14:36:27-05:00</dc:date>
            <dcterms:modified>2010-07-09T14:38:21-05:00</dcterms:modified>
            <dc:creator>Stephen Kost</dc:creator>
            
            
            <dc:subject>Oracle Database</dc:subject>
            
            
            <dc:subject>Oracle Critical Patch Update</dc:subject>
            
            
            <dc:subject>Oracle E-Business Suite</dc:subject>
            
        </item>
        
        
        <item rdf:about="http://www.integrigy.com/oracle-security-blog/archive/2010/05/25/ioug-webinar-database-security">
            <title>Upcoming IOUG Webinar - A Journey Through Enterprise Database Security for DBAs</title>
            <link>http://www.integrigy.com/oracle-security-blog/archive/2010/05/25/ioug-webinar-database-security</link>
            
            <p:payload xmlns="http://www.w3.org/1999/xhtml"
                       rdf:parseType="Literal">Integrigy's CTO, Stephen Kost, will be presenting an <a href="http://www.ioug.org">Independent Oracle User's Group (IOUG)</a> educational webinar as part of IOUG's Database Security Technical Education Series.<br /><br /><span style="font-weight: bold;">A Journey Through Enterprise Database Security for DBAs</span><br />Stephen Kost, Integrigy<br />Wednesday, May 26, 1:00pm - 2:00pm CT<br /><br />This presentation is intended for Database Administrators. It will detail the enterprise database security requirements, regulatory requirements and monitoring of databases.<br /><br />Click <a href="https://www1.gotomeeting.com/register/701306992">here</a> to register for the webinar.<br /><br />The webinar is free for IOUG Full Members and $49 for Associate Members and Non-members.</p:payload>
            <dc:date>2010-05-25T16:58:07-05:00</dc:date>
            <dcterms:modified>2010-05-25T16:58:07-05:00</dcterms:modified>
            <dc:creator>Stephen Kost</dc:creator>
            
            
            <dc:subject>Oracle Database</dc:subject>
            
        </item>
        
        
        <item rdf:about="http://www.integrigy.com/oracle-security-blog/archive/2010/04/15/collaborate10-virtual">
            <title>Integrigy Oracle CPU Virtual Session Live from COLLABORATE 10</title>
            <link>http://www.integrigy.com/oracle-security-blog/archive/2010/04/15/collaborate10-virtual</link>
            
            <p:payload xmlns="http://www.w3.org/1999/xhtml"
                       rdf:parseType="Literal">For those of you unable to attend the OAUG/IOUG COLLABORATE 10 User Conference in Las Vegas next week, the conference is offering a virtual experience of the conference.&nbsp; There will be 41 sessions available via webinar live from Las Vegas.&nbsp; Integrigy is pleased to announce that the following session is included in the roster of <a href="http://collaborate10.ioug.org/Education/PlugintoVegas/tabid/139/Default.aspx">Plug-in to Vegas</a> virtual sessions -<br /><br /><span class="link-external"><a href="http://coll10.mapyourshow.com/2_3/sessions/result_V2_3.cfm?CFID=14015500&amp;CFTOKEN=a49f099a68f7fa3c-439C3872-BA43-A3B3-2F8CAE7650F5B0FC&amp;q=&amp;AudienceID=+&amp;SessionTypeID=+&amp;SpeakerID=215&amp;TrackID=+&amp;Date=+&amp;StartTime=+&amp;EndTime=+&amp;commit=Search">Oracle  Critical Patch Updates Unwrapped<br /></a></span>Session #330<br />Tuesday,  April 20, 2010<br />2:00pm - 3:00pm</p:payload>
            <dc:date>2010-04-15T22:03:38-05:00</dc:date>
            <dcterms:modified>2010-04-15T22:06:22-05:00</dcterms:modified>
            <dc:creator>Stephen Kost</dc:creator>
            
            
            <dc:subject>COLLABORATE</dc:subject>
            
            
            <dc:subject>Oracle Critical Patch Update</dc:subject>
            
        </item>
        
        
        <item rdf:about="http://www.integrigy.com/oracle-security-blog/archive/2010/03/30/collaborate10">
            <title>Integrigy at COLLABORATE 10</title>
            <link>http://www.integrigy.com/oracle-security-blog/archive/2010/03/30/collaborate10</link>
            
            <p:payload xmlns="http://www.w3.org/1999/xhtml"
                       rdf:parseType="Literal">
<div class="weblog-topic-images"><a href="../../../2009/oracle-security-blog/topics/COLLABORATE"></a></div>

<div class="plain">For those of you not familiar with COLLABORATE or have not previously attended, the Oracle Applications Users Group (OAUG), Independent Oracle Users Group (IOUG), and Quest have teamed together to host a user-driven event with exceptional content.&nbsp; COLLABORATE 10 is Sunday, April 18, 2010 through Thursday, April 22, 2010 in Las Vegas.&nbsp; This year there will be over 1,000 technical sessions covering virtually every Oracle product.&nbsp; <br /><br />If you are attending and would like to chat about the latest developments in Oracle security or discuss specific security challenges you might be facing, drop me a note and we can arrange to meet.<br /><br />Integrigy's CTO, Stephen Kost, will be presenting three technical sessions on securing Oracle products and participating on two panels.<br /><br />
<h3>Oracle Applications Users Group (OAUG) </h3>
<br /><a href="http://coll10.mapyourshow.com/2_3/sessions/result_V2_3.cfm?CFID=14015500&amp;CFTOKEN=a49f099a68f7fa3c-439C3872-BA43-A3B3-2F8CAE7650F5B0FC&amp;q=&amp;AudienceID=+&amp;SessionTypeID=+&amp;SpeakerID=215&amp;TrackID=+&amp;Date=+&amp;StartTime=+&amp;EndTime=+&amp;commit=Search">Leveraging Oracle Database Security Technologies with Oracle E-Business Suite</a><br />Session #4556<br />Monday, April 19, 2010<br />10:45am - 11:45am<br /><br /><a href="http://coll10.mapyourshow.com/2_3/sessions/result_V2_3.cfm?CFID=14015500&amp;CFTOKEN=a49f099a68f7fa3c-439C3872-BA43-A3B3-2F8CAE7650F5B0FC&amp;q=&amp;AudienceID=+&amp;SessionTypeID=+&amp;SpeakerID=215&amp;TrackID=+&amp;Date=+&amp;StartTime=+&amp;EndTime=+&amp;commit=Search">Panel: Governance, Risk &amp; Compliance SIG Meeting<br /></a>Session #4699<br />Tuesday, April 20, 2010<br />8:00am - 9:00am<br /><br /><a href="http://coll10.mapyourshow.com/2_3/sessions/result_V2_3.cfm?CFID=14015500&amp;CFTOKEN=a49f099a68f7fa3c-439C3872-BA43-A3B3-2F8CAE7650F5B0FC&amp;q=&amp;AudienceID=+&amp;SessionTypeID=+&amp;SpeakerID=215&amp;TrackID=+&amp;Date=+&amp;StartTime=+&amp;EndTime=+&amp;commit=Search">Panel: Securing the E-Business Suite - Expert And Best Practices Panel<br /></a>Session #3676<br />Wednesday, April 21, 2010<br />9:15am - 10:15am<br /><br />
<h3>Independent Oracle Users Group (IOUG)</h3>
<br /><a href="http://coll10.mapyourshow.com/2_3/sessions/result_V2_3.cfm?CFID=14015500&amp;CFTOKEN=a49f099a68f7fa3c-439C3872-BA43-A3B3-2F8CAE7650F5B0FC&amp;q=&amp;AudienceID=+&amp;SessionTypeID=+&amp;SpeakerID=215&amp;TrackID=+&amp;Date=+&amp;StartTime=+&amp;EndTime=+&amp;commit=Search">Oracle Critical Patch Updates Unwrapped<br /></a>Session #330<br />Tuesday, April 20, 2010<br />2:00pm - 3:00pm<br /><br /><a href="http://coll10.mapyourshow.com/2_3/sessions/result_V2_3.cfm?CFID=14015500&amp;CFTOKEN=a49f099a68f7fa3c-439C3872-BA43-A3B3-2F8CAE7650F5B0FC&amp;q=&amp;AudienceID=+&amp;SessionTypeID=+&amp;SpeakerID=215&amp;TrackID=+&amp;Date=+&amp;StartTime=+&amp;EndTime=+&amp;commit=Search">Is Your Auditing Failing You?<br /></a>Session #600<br />Thursday, April 22, 2010<br />11:00am - 12:00pm<br />(Note: the time for this presentation has changed)<br /><br />See you in Las Vegas!</div></p:payload>
            <dc:date>2010-03-30T09:18:41-05:00</dc:date>
            <dcterms:modified>2010-04-15T22:07:30-05:00</dcterms:modified>
            <dc:creator>Stephen Kost</dc:creator>
            
            
            <dc:subject>COLLABORATE</dc:subject>
            
        </item>
        
        
        <item rdf:about="http://www.integrigy.com/oracle-security-blog/archive/2010/01/08/cpu-january-2010-prerelease">
            <title>Oracle Critical Patch Update January 2010 Pre-Release Analysis</title>
            <link>http://www.integrigy.com/oracle-security-blog/archive/2010/01/08/cpu-january-2010-prerelease</link>
            
            <p:payload xmlns="http://www.w3.org/1999/xhtml"
                       rdf:parseType="Literal">Here is a brief analysis of the <a href="http://www.oracle.com/technology/deploy/security/alerts.htm">pre-release announcement</a> for the upcoming January 2010 Oracle Critical Patch Update (CPU) -<br />
<ul>
    <li>Overall, 24 security vulnerabilities are fixed in this CPU, which is a below average number but well within the range of previous CPUs (Oct-09=38, Jul-09=30, Apr-09=43, Jan-09=41, Oct-08=36, Jul-08=45, Apr-08=41, Jan-08=26, Oct-07=51, Jul-07=45, Apr-07=36, Jan-07=51, Oct-06=101, Jul-06=62, Apr-06=34, Jan-06=80).</li>
    <li>The product and vulnerability mix appears to be similar to previous CPUs.&nbsp; All <span style="font-weight: bold; text-decoration: underline;">CPU supported</span> Oracle Database, Oracle Application Server, and Oracle E-Business Suite versions are included.&nbsp; The list of supported versions is getting very short and should be carefully reviewed to determine if version upgrades are required prior to applying the CPU security patches -</li>
    <ul>
        <ul>
            <ul>
                <li>Database = 9.2.0.8, 10.1.0.5, 10.2.0.3, 10.2.0.4, and 11.1.0.7 for major platforms<br /></li>
                <li>Application Server = 9.0.4.3, 10.1.2, and 10.1.3</li>
                <li>E-Business Suite = 11.5.10.x, 12.0.x, and 12.1.x<br /></li>
            </ul>
        </ul>
    </ul>
    <li><span style="font-weight: bold;">The highlight of this CPU are 2 remotely exploitable without authentication vulnerabilities in the Oracle Database</span>.&nbsp; It is rare to have a single remotely exploitable without authentication vulnerability in the database.&nbsp; Most likely these 2 vulnerabilities are in the Listener, APEX Application Builder, and/or Secure Backup.&nbsp; If the remotely exploitable vulnerabilities are in the Listener component, then this could be a significant and high priority CPU. </li>
    <li>There are no major version support changes in for this CPU.<br /></li>
</ul>
<br /> <span style="font-weight: bold; text-decoration: underline;">Oracle Database</span><br />
<ul>
    <li>There are 10 database vulnerabilities and two are remotely exploitable without authentication.<br /></li>
    <li>Since at least one database vulnerability has a <a href="http://www.integrigy.com/oracle-security-blog/archive/2006/10/27/oracle-cvss">CVSS</a> 2.0 metric of 10.0, this is a strong indication there a buffer overflow in the Listener component that is remotely exploitable without authentication.&nbsp; Most likely, the CVSS metric for Windows will be 10.0 and will be 7.5 for Unix/Linux (even though you will be able to fully compromise the database).</li>
</ul>
<span style="font-weight: bold; text-decoration: underline;">Oracle Application Server</span><br />
<ul>
    <li>There are three new Oracle Application Server vulnerabilities, all of which are remotely exploitable without authentication.&nbsp; The affected components are Access Manager Identify Server and Oracle Containers for J2EE.&nbsp; With maximum <a href="http://www.integrigy.com/oracle-security-blog/archive/2006/10/27/oracle-cvss">CVSS</a> 2.0 metric of 5.0, these could be cross-site scripting (XSS) vulnerabilities based on the scores and components.<br /></li>
</ul>
<br /><span style="font-weight: bold; text-decoration: underline;">Oracle E-Business Suite 11i and R12</span>
<ul>
    <li>There are 3 new Oracle E-Business Suite 11i and R12 vulnerabilities, all of which are remotely exploitable without authentication.</li>
    <li>The vulnerabilities are in the CRM Technical Foundation (mobile), AOL, and HRMS.&nbsp; Of most interest will be if the AOL vulnerability is in an externally accessible web page.<br /></li>
</ul>
<br /><span style="font-weight: bold; text-decoration: underline;">Planning Impact</span><br />
<ul>
    <li>The criticality of this quarter's CPU is in-line with previous CPUs.&nbsp; <br /></li>
    <li>As with all previous CPUs, this quarter's security patches should be deemed critical and you should adhere to the established procedures and timing used for previous CPUs.</li>
</ul></p:payload>
            <dc:date>2010-01-08T09:21:47-06:00</dc:date>
            <dcterms:modified>2010-01-08T09:21:47-06:00</dcterms:modified>
            <dc:creator>Stephen Kost</dc:creator>
            
            
            <dc:subject>Oracle Database</dc:subject>
            
            
            <dc:subject>Oracle Critical Patch Update</dc:subject>
            
            
            <dc:subject>Oracle E-Business Suite</dc:subject>
            
        </item>
        
        
        <item rdf:about="http://www.integrigy.com/oracle-security-blog/archive/2009/07/31/oracle-cpu-october-2009-r12">
            <title>Oracle Critical Patch Update October 2009 - 12.0.3 or Higher Only</title>
            <link>http://www.integrigy.com/oracle-security-blog/archive/2009/07/31/oracle-cpu-october-2009-r12</link>
            
            <p:payload xmlns="http://www.w3.org/1999/xhtml"
                       rdf:parseType="Literal">For those of you who didn't read the Oracle Critical Patch Update (CPU) July 2009 Oracle E-Business Suite documentation (Metalink Note ID <a href="https://metalink2.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&amp;p_id=836258.1">836258.1</a>) closely enough, Oracle has now established a minimum baseline for R12.<br /><br />Starting with the October 2009 Critical Patch Update -<br /><br />
<p class="callout">The new minimum supported baseline will be Release 12.0.3; that is, Oracle E-Business Suite Critical Patch Updates will only be available for customers on Release 12.0.3 or higher.<br /></p>
This is a significant update for some customers due to the size and impact of the patch.</p:payload>
            <dc:date>2009-07-31T10:01:35-05:00</dc:date>
            <dcterms:modified>2009-07-31T10:01:35-05:00</dcterms:modified>
            <dc:creator>Stephen Kost</dc:creator>
            
            
            <dc:subject>Oracle E-Business Suite</dc:subject>
            
            
            <dc:subject>Oracle Critical Patch Update</dc:subject>
            
        </item>
        
        
        <item rdf:about="http://www.integrigy.com/oracle-security-blog/archive/2009/07/31/oracle-cpu-october-2009-rup7">
            <title>Oracle Critical Patch Update October 2009 - 11i ATG RUP6 or RUP7 Only</title>
            <link>http://www.integrigy.com/oracle-security-blog/archive/2009/07/31/oracle-cpu-october-2009-rup7</link>
            
            <p:payload xmlns="http://www.w3.org/1999/xhtml"
                       rdf:parseType="Literal">Oracle has officially released the latest Oracle Applications Technology update patch which is formally known as Oracle Applications Technology 11i.ATG_PF.H.delta.7 (RUP7).&nbsp; The patch number is <a>6241631</a>.<br /><br />The Oracle policy for Oracle E-Business Suite 11i Critical Patch Updates is very clear -<br /><br />
<p class="callout">Oracle Applications Technology (ATG) Minimum Supported Baseline:<br /><br />Beginning with the July 2007 Critical Patch Update (CPUJul2007), Oracle Applications Technology only supports the current and previous production rollups (RUPn and RUPn-1) as patching baselines for all 11i releases.<br /></p>
With the release of ATG RUP7, the minimum supported baseline for the October 2009 Critical Patch Update (CPU) will be ATG RUP6 or RUP7.&nbsp; Therefore, in order to apply the October 2009 Oracle EBS CPU patches, you must be on RUP6 or RUP7.<br /><br />One advantage of applying RUP7 is that it contains Oracle Applications Technology (ATG) security fixes for core ATG products from the January 2005 Critical Patch Update (CPUJan2005) through the July 2009  Critical Patch Update (CPUJul2009).&nbsp; The following core ATG products are included in 11i.ATG_PF.H.delta.7: FND, OAM, OWF, FWK, JTT, JTA, TXK, XDO, ECX, EC, AK, ALR, UMX, BNE, and FRM.&nbsp; Note that this is a large subset of the 11i CPU patches, but does not include any functional module patches such as AP, iStore, etc.&nbsp; You still must review all previous CPUs for missing EBS CPU patches.</p:payload>
            <dc:date>2009-07-31T09:52:03-05:00</dc:date>
            <dcterms:modified>2009-07-31T09:52:50-05:00</dcterms:modified>
            <dc:creator>Webmaster</dc:creator>
            
            
            <dc:subject>Oracle E-Business Suite</dc:subject>
            
            
            <dc:subject>Oracle Critical Patch Update</dc:subject>
            
        </item>
        
        
        <item rdf:about="http://www.integrigy.com/oracle-security-blog/archive/2009/07/15/oracle-cpu-july-2009">
            <title>Oracle Critical Patch Update (CPU) - July 2009 - E-Business Suite Impact</title>
            <link>http://www.integrigy.com/oracle-security-blog/archive/2009/07/15/oracle-cpu-july-2009</link>
            
            <p:payload xmlns="http://www.w3.org/1999/xhtml"
                       rdf:parseType="Literal">Oracle released the nineteenth Critical Patch Update (CPU) on Tuesday, July 14, 2009 (CPU July 2009/CPUJul09). This quarter is the same as the previous eighteen with many patches and long hours in order to get all the security patches applied in a timely manner. Around 12 of the 30 vulnerabilities fixed impact the Oracle E-Business Suite.&nbsp; Fortunately like the last few quarters, this quarter there are no new Oracle Application Server or Developer 6i patches required for the Oracle E-Business Suite 11i. <br /><br />The most interesting database vulnerabilities this quarter are three vulnerabilities in the network components of the Oracle Database (CVE-2009-1020, CVE-2009-1019, CVE-2009-1963).&nbsp; One of these vulnerabilities (CVE-2009-1019) is remotely exploitable without authentication.<br /><br />For Internet-facing Oracle E-Business Suite environments, CVE-2009-1980 AOL, CVE-2009-1982 OAF, and CVE-2009-1983 iStore are all externally accessible and two are remotely exploitable without authentication.&nbsp; These customers should carefully review these vulnerabilities and patch as soon as possible.<br /><br />Oracle continues the push to keep all customers on recent versions by only certifying the CPU patches with 9.2.0.8, 10.1.0.5, 10.2.0.4, 11.1.0.6, and 11.1.0.7 for the database and ATG_PF.H RUP5 or RUP6 for the Oracle E-Business Suite 11i. <br /><br />More information about the vulnerabilities and detailed recommendations on patching and testing is available at -  <br /><br /><a href="http://www.integrigy.com/security-resources/analysis/Integrigy-Oracle-CPU-July-2009-Analysis.pdf">Oracle Oracle Critical Patch Update - July 2009 - E-Business Suite Impact</a></p:payload>
            <dc:date>2009-07-15T14:12:46-05:00</dc:date>
            <dcterms:modified>2009-07-16T09:39:25-05:00</dcterms:modified>
            <dc:creator>Stephen Kost</dc:creator>
            
            
            <dc:subject>Oracle Database</dc:subject>
            
            
            <dc:subject>Oracle Critical Patch Update</dc:subject>
            
            
            <dc:subject>Oracle E-Business Suite</dc:subject>
            
        </item>
        
        
        <item rdf:about="http://www.integrigy.com/oracle-security-blog/archive/2009/07/13/cpu-july-2009-prerelease">
            <title>Oracle Critical Patch Update July 2009 Pre-Release Analysis</title>
            <link>http://www.integrigy.com/oracle-security-blog/archive/2009/07/13/cpu-july-2009-prerelease</link>
            
            <p:payload xmlns="http://www.w3.org/1999/xhtml"
                       rdf:parseType="Literal">Here is a brief analysis of the <span class="link-external"><span class="link-external"><a href="http://www.oracle.com/technology/deploy/security/alerts.htm">pre-release announcement</a></span></span> for the upcoming July 2009 Oracle Critical Patch Update (CPU) -<br />
<ul>
    <li>Overall, 33 security vulnerabilities are fixed in this CPU, which is an average number well within the range of previous CPUs (Apr-09=43, Jan-09=41, Oct-08=36, Jul-08=45, Apr-08=41, Jan-08=26, Oct-07=51, Jul-07=45, Apr-07=36, Jan-07=51, Oct-06=101, Jul-06=62, Apr-06=34, Jan-06=80).</li>
    <li>The product and vulnerability mix appears to be similar to previous CPUs.&nbsp; All <span style="font-weight: bold; text-decoration: underline;">CPU supported</span> Oracle Database, Oracle Application Server, and Oracle E-Business Suite versions are included.&nbsp; The list of supported versions is getting very short and should be carefully reviewed to determine if version upgrades are required prior to applying the CPU security patches -</li>
    <ul>
        <ul>
            <ul>
                <li>Database = 9.2.0.8, 10.1.0.5, 10.2.0.3, 10.2.0.4, 11.1.0.6, and 11.1.0.7 for major platforms<br /></li>
                <li>Application Server = 9.0.4.3, 10.1.2, and 10.1.3</li>
                <li>E-Business Suite = 11.5.10.x, 12.0.x, and 12.1.x<br /></li>
            </ul>
        </ul>
    </ul>
    <li><span style="font-weight: bold;">The highlight of this CPU are 3 remotely exploitable without authentication vulnerabilities in the Oracle Database</span>.&nbsp; It is rare to have a single remotely exploitable without authentication vulnerability in the database and having three such vulnerabilities could make this a significant and high priority CPU.&nbsp; Most likely these 3 vulnerabilities are in the Listener, Network Authentication, and Network Foundation components.<br /></li>
    <li>There are no major version support changes in for this CPU.<br /></li>
</ul>
<br /> <span style="font-weight: bold; text-decoration: underline;">Oracle Database</span><br />
<ul>
    <li>There are 10 database vulnerabilities and three are remotely exploitable without authentication.&nbsp; As previously noted, the three remotely exploitable without authentication vulnerabilities could make this one of the most critical quarterly releases in the past three years.</li>
    <li>The three remotely exploitable without authentication vulnerabilities are most likely in the Listener, Network Authentication, and Network Foundation components.&nbsp; One of these vulnerabilities has a <span class="link-external"><a href="http://www.integrigy.com/oracle-security-blog/archive/2006/10/27/oracle-cvss">CVSS</a></span> 2.0 metric of 9.0, thus making this a highly critical patch.</li>
    <li>Similar to the January 2009 CPU, there are two critical vulnerabilities (one remotely exploitable without authentication and a CVSS 2.0 metric of 10). </li>
</ul>
<span style="font-weight: bold; text-decoration: underline;">Oracle Application Server</span><br />
<ul>
    <li>There are two new Oracle Application Server vulnerabilities, both of which are remotely exploitable without authentication.&nbsp; In previous CPUs, the majority of Oracle Application Server vulnerabilities have tended to be remotely exploitable without authentication.&nbsp; The vulnerabilities are in the Core HTTP Server (Apache) and the <span class="draft">Oracle Security Developer Tools</span>.&nbsp; The highest CVSS 2.0 metric is a 5.0 suggesting that these are only of limited risk.&nbsp; For the Oracle HTTP Server which is based on Apache, Oracle provides security fixes for previously released Apache vulnerabilities several month later.&nbsp; Most likely this Core HTTP Server vulnerability is a fix for a previously released Apache vulnerability.<br /></li>
</ul>
<br /><span style="font-weight: bold; text-decoration: underline;">Oracle E-Business Suite 11i and R12</span>
<ul>
    <li>There are 8 new Oracle E-Business Suite 11i and R12 vulnerabilities and five are remotely exploitable without authentication.</li>
    <li>Of most interest are the iSupplier Portal and iStore vulnerabilities, which may require immediate patching for Internet-facing implementations.</li>
    <li>This is the first CPU with a patch for 12.1.</li>
</ul>
<br /><span style="font-weight: bold; text-decoration: underline;">Planning Impact</span><br />
<ul>
    <li>The criticality of this quarter's CPU may be higher for the Oracle Database than previous CPUs.&nbsp; <br /></li>
    <li>As with all previous CPUs, this quarter's security patches should be deemed critical and you should adhere to the established procedures and timing used for previous CPUs.</li>
</ul></p:payload>
            <dc:date>2009-07-13T14:18:28-05:00</dc:date>
            <dcterms:modified>2009-07-13T14:18:28-05:00</dcterms:modified>
            <dc:creator>Stephen Kost</dc:creator>
            
            
            <dc:subject>Oracle Database</dc:subject>
            
            
            <dc:subject>Oracle Critical Patch Update</dc:subject>
            
            
            <dc:subject>Oracle E-Business Suite</dc:subject>
            
        </item>
        
        
        <item rdf:about="http://www.integrigy.com/oracle-security-blog/archive/2009/06/16/oracle-cpu-rup7">
            <title>11i ATG RUP7 and Critical Patch Updates Impact</title>
            <link>http://www.integrigy.com/oracle-security-blog/archive/2009/06/16/oracle-cpu-rup7</link>
            
            <p:payload xmlns="http://www.w3.org/1999/xhtml"
                       rdf:parseType="Literal">Oracle has <a href="http://blogs.oracle.com/stevenChan/2009/06/interim_update_atg_rup_7_for_ebusiness_release_11i.html">hinted</a> at the upcoming release of Oracle E-Business Suite 11i.ATG_PF.H.delta.7 (or commonly referred to as RUP7) and will be most likely available in the next several months as it is currently under going internal testing.&nbsp; Oracle Critical Patch Update patches for Oracle E-Business Suite 11i have the latest ATG RUP patches as a prerequisite - the official prerequisite is RUP N or RUP N-1 is required.&nbsp; The last RUP was ATG RUP6 (5903765) released in October 2007.&nbsp; <br /><br />Currently for April 2009 CPU patches, RUP5 or RUP6 is required.&nbsp; Due to timing, most likely for July 2009 CPU patches, RUP5 or RUP6 will be required.&nbsp; <span style="font-weight: bold; color: rgb(0, 0, 255);">For planning purposes, it should be assumed that for October 2009 CPU patches, only RUP6 and RUP7 will be supported.</span><br /><br />Also, since April 2009 and for all future CPUs, the only 11i CPU supported database versions are 9.2.0.8, 10.1.0.5, 10.2.0.4, and 11.1.0.7.</p:payload>
            <dc:date>2009-06-16T10:30:03-05:00</dc:date>
            <dcterms:modified>2009-06-16T10:30:42-05:00</dcterms:modified>
            <dc:creator>Stephen Kost</dc:creator>
            
            
            <dc:subject>Oracle E-Business Suite</dc:subject>
            
            
            <dc:subject>Oracle Critical Patch Update</dc:subject>
            
        </item>
        
        
        <item rdf:about="http://www.integrigy.com/oracle-security-blog/archive/2009/05/07/collaborate09-presentations">
            <title>COLLABORATE 09 Integrigy Presentations</title>
            <link>http://www.integrigy.com/oracle-security-blog/archive/2009/05/07/collaborate09-presentations</link>
            
            <p:payload xmlns="http://www.w3.org/1999/xhtml"
                       rdf:parseType="Literal">The COLLABORATE 09 conference has completed and from all accounts was a success.&nbsp; For those of you not familiar with COLLABORATE, the Oracle Applications Users Group (OAUG), Independent Oracle Users Group (IOUG), and Quest have teamed together to host a user-driven event with exceptional content.&nbsp; This year's conference had over 1,000 technical sessions covering virtually every Oracle product.&nbsp; Integrigy delivered 3 security related presentations and I have upload the presentations to our Security Resources section under Whitepapers and Presentations.&nbsp; Here are the links -<br /><br />
<h3>Oracle Applications Users Group (OAUG) </h3>
<span class="link-external"><span class="link-external"><a href="/security-resources/whitepapers/OAUG-Integrigy-Oracle-Critical-Patch-Updates-Unwrapped.pdf/view"><span style="font-weight: bold; text-decoration: underline;">Oracle Critical Patch Updates Unwrapped</span></a></span></span><br /><br /><br />
<h3>Independent Oracle Users Group (IOUG)</h3>
<br /><span class="link-external"><span class="link-external"><a href="/security-resources/whitepapers/IOUG-Integrigy-Oracle-Critical-Patch-Updates-Insight-Understanding.pdf/view"><span style="font-weight: bold; text-decoration: underline;">Oracle Critical Patch Updates: Insight and Understanding</span></a></span></span><br /><br /><span class="link-external"><span class="link-external"><a href="/security-resources/whitepapers/Integirgy-IOUG-2009-Real-World-Database-Auditing.pdf/view"><span style="font-weight: bold;">Real World Database Auditing</span></a><br /><br /></span></span></p:payload>
            <dc:date>2009-05-07T14:16:25-05:00</dc:date>
            <dcterms:modified>2009-05-07T14:17:19-05:00</dcterms:modified>
            <dc:creator>Stephen Kost</dc:creator>
            
            
            <dc:subject>COLLABORATE</dc:subject>
            
            
            <dc:subject>Oracle E-Business Suite</dc:subject>
            
            
            <dc:subject>Oracle Database</dc:subject>
            
        </item>
        
        
        <item rdf:about="http://www.integrigy.com/oracle-security-blog/archive/2009/04/29/collaborate09">
            <title>Integrigy at COLLABORATE 09</title>
            <link>http://www.integrigy.com/oracle-security-blog/archive/2009/04/29/collaborate09</link>
            
            <p:payload xmlns="http://www.w3.org/1999/xhtml"
                       rdf:parseType="Literal">For those of you not familiar with COLLABORATE or have not previously attended, the Oracle Applications Users Group (OAUG), Independent Oracle Users Group (IOUG), and Quest have teamed together to host a user-driven event with exceptional content.&nbsp; COLLABORATE 09 is next week, Sunday, May 3 through Thursday, May 7 in Orlando.&nbsp; This year there will be over 1,000 technical sessions covering virtually every Oracle product.&nbsp; <br /><br />Integrigy's CTO, Stephen Kost, will be presenting three technical sessions:<br /><br />
<h3>Oracle Applications Users Group (OAUG) </h3>
<br /><span class="link-external"><a href="http://onramp.meetingexpectations.com/Presentation/PresentationDetails.aspx?EventID=8V0QuCm%2bztrjQMVAnzV5%2fw%3d%3d&amp;SessionID=DZ9mjtmH9mS0W8CtFtv0Zw%3d%3d"><span style="font-weight: bold; text-decoration: underline;"> Oracle Critical Patch Updates Unwrapped</span></a></span><br />Session #1936<br />Wednesday, May 6, 2009<br />9:45am - 10:45am<br /><br />
<h3>Independent Oracle Users Group (IOUG)</h3>
<br /><span class="link-external"><a href="http://submissions.miracd.com/ioug2009/Itinerary/ItineraryAAGDetail.asp?EventID=198&amp;iGroupID=-1"><span style="font-weight: bold; text-decoration: underline;">Oracle Critical Patch Updates: Insight and Understanding</span></a></span><br />Session #359<br />Wednesday, May 6, 2008<br />8:30am - 9:30am<br /><br /><span class="link-external"><a href="http://submissions.miracd.com/ioug2009/Itinerary/ItineraryAAGDetail.asp?EventID=121&amp;iGroupID=-1"><span style="font-weight: bold; text-decoration: underline;">Real World Database Auditing</span></a></span><br />Session #602<br />Tuesday, May 5, 2009<br />11:00 AM - 12:00 PM<br /><br />See you in Orlando!</p:payload>
            <dc:date>2009-04-29T19:56:39-05:00</dc:date>
            <dcterms:modified>2009-05-07T14:13:04-05:00</dcterms:modified>
            <dc:creator>Stephen Kost</dc:creator>
            
            
            <dc:subject>COLLABORATE</dc:subject>
            
        </item>
        
        
        <item rdf:about="http://www.integrigy.com/oracle-security-blog/archive/2009/04/17/oracle-cpu-april-2009">
            <title>Oracle Critical Patch Update - April 2009 - E-Business Suite Impact</title>
            <link>http://www.integrigy.com/oracle-security-blog/archive/2009/04/17/oracle-cpu-april-2009</link>
            
            <p:payload xmlns="http://www.w3.org/1999/xhtml"
                       rdf:parseType="Literal">Oracle released the eighteenth Critical Patch Update (CPU) on Tuesday, April 14, 2009 (CPU April 2009/CPUApr09). This quarter is the same as the previous sixteen with many patches and long hours in order to get all the security patches applied in a timely manner. Around 20 of the 43 vulnerabilities fixed impact the Oracle E-Business Suite.&nbsp; Fortunately like the last few quarters, this quarter there are no new Oracle Application Server or Developer 6i patches required for the Oracle E-Business Suite 11i. <br /><br />Again this quarter there are a number of database vulnerabilities that can be exploited by lowly privileged database accounts, including the APPLSYSPUB account.&nbsp; Also, there are 2 denial of service vulnerabilities - one in the database listener and the other in the RAC Cluster Ready Services. <br /><br />For the Application Server, no action is required for Oracle E-Business Suite 11i.&nbsp; For R12, there is a serious vulnerability in OPMN which is installed and used and multiple issues in BI Publisher (formerly XML Publisher).<br /><br />Oracle continues the push to keep all customers on recent versions by only certifying the CPU patches with 9.2.0.8, 10.1.0.5, 10.2.0.4, 11.1.0.6, and 11.1.07 for the database and ATG_PF.H RUP5 or RUP6 for the Oracle E-Business Suite 11i. <br /><br />More information about the vulnerabilities and detailed recommendations on patching and testing is available at -  <br /><br /><a href="http://www.integrigy.com/security-resources/analysis/Integrigy-Oracle-CPU-April-2009-Analysis.pdf">Oracle Oracle Critical Patch Update - April 2009 - E-Business Suite Impact</a></p:payload>
            <dc:date>2009-04-17T15:03:06-05:00</dc:date>
            <dcterms:modified>2009-04-17T15:03:06-05:00</dcterms:modified>
            <dc:creator>Stephen Kost</dc:creator>
            
            
            <dc:subject>Oracle E-Business Suite</dc:subject>
            
            
            <dc:subject>Oracle Critical Patch Update</dc:subject>
            
        </item>
        
    </items>
</Channel>

