Oracle suddenly revealed a security error

Picture 1 of Oracle suddenly revealed a security error Oracle database software vendor last week unexpectedly provided details of an unpatched security hole in its products.

As usual, Oracle often keeps secrets about security flaws as well as the names of researchers who discovered security holes in Oracle products. However, Alexander Kornbrust, an expert in Oracle's security issues, said on April 6, Oracle unveiled an unpatched security vulnerability.

Oracle has confirmed the surprise for disclosing details of this security error. ' Information related to security vulnerabilities has been unexpectedly published ,' an Oracle representative said. ' We are currently investigating this incident .'

This published security hole primarily affects the Oracle database software versions from 9.1.0.0 to 10.2.0.3 operating on any operating system version.

Not only does it give details of security flaws, but also code snippets to test security flaws, Kornbrust said.

The link pointing to details about this security error has been removed. But when it has been specifically announced, it is certain that information about this security has been widely available.

' Any developer and database administrator who is not aware of the published information should learn more about this security error in order to avoid the risk of exploitation and should wait for another copy. New patch from Oracle , 'Kornbrust recommends.

This security error can be exploited to increase access to the database. This means that users with limited access to the database can take advantage of this security error to gain more rights. ' Depending on the architecture of the application, increasing access may allow for wider access, even changing data - for example, changing the database password , Kornbrust said.

This security error stems from an error in handling 'views' of some users with limited access. This security error is only classified as normal.

Oracle currently has no fixes for this security bug. However, it is expected that the security patch released yesterday includes this patch.

Hoang Dung