Errors in Oracle password protection system

Picture 1 of Errors in Oracle password protection system Security experts have warned about the risk of hackers recovering Oracle database passwords due to weaknesses in the security mechanism of this package.

The flaw could put many Oracle customers in jeopardy of the threat of hackers. According to the SANS Institute of Technology, Oracle should " restore " the password protection engine to database users because they have discovered Oracle's even better encrypted password recovery.

SANS experts have informed Oracle of this security flaw since July 2005, but so far no response has been received from this company. About 1 month ago, the news website CNet also posted news about the vulnerability and notified Oracle but did not receive a reply.

SANS recommends administering Oracle database should use more complex passwords than normal and assign limited permissions to users to protect safety while waiting for Oracle's fixes.

VH - ( ZDNet )