Oracle suddenly revealed a security error
Oracle database software vendor last week unexpectedly provided details of an unpatched security hole in its products.
As usual, Oracle often keeps secrets about security flaws as well as the names of researchers who discovered security holes in Oracle products. However, Alexander Kornbrust, an expert in Oracle's security issues, said on April 6, Oracle unveiled an unpatched security vulnerability.
Oracle has confirmed the surprise for disclosing details of this security error. ' Information related to security vulnerabilities has been unexpectedly published ,' an Oracle representative said. ' We are currently investigating this incident .'
This published security hole primarily affects the Oracle database software versions from 9.1.0.0 to 10.2.0.3 operating on any operating system version.
Not only does it give details of security flaws, but also code snippets to test security flaws, Kornbrust said.
The link pointing to details about this security error has been removed. But when it has been specifically announced, it is certain that information about this security has been widely available.
This security error can be exploited to increase access to the database. This means that users with limited access to the database can take advantage of this security error to gain more rights. ' Depending on the architecture of the application, increasing access may allow for wider access, even changing data - for example, changing the database password , Kornbrust said.
This security error stems from an error in handling 'views' of some users with limited access. This security error is only classified as normal.
Oracle currently has no fixes for this security bug. However, it is expected that the security patch released yesterday includes this patch.
Hoang Dung
- 10 worst moments of security industry
- Oracle patched 101 security holes
- 65 Oracle product security errors have been fixed
- An Oracle error exploit code appears
- Oracle has 23 security holes in applications
- Errors in Oracle password protection system
- Microsoft: 'ActiveX error is just a mediocre error'
- Drag-and-drop security error in IE
- Where does the error 'Error 404' come from?
- Error OpenOffice interconnects multiple operating systems
- Oracle purchased 2 companies that provide solutions to strengthen security products
- Find a security error, reward 10,000 USD