Call: +44 (0)1904 557620 Call
Blog

Pete Finnigan's Oracle Security Weblog

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

[Previous entry: "Oracle will improve the CPU documentation with the Oct 17th 2006 CPU"] [Next entry: "SANS Oracle S.C.O.R.E. document has been updated"]

Security bug in 10.2.0.2 not fixed yet



I saw a post on the pythian blog today titled http://www.pythian.com/blogs/254/oracle-patch-10203-bugs-weve-seen - (broken link) Oracle Patch 10.2.0.3 - Bugs We’ve Seen and went for a look. The interesting part for me was the link to a post on metalink describing a security but that in the right circumstances allows SQL statements to be executed under the wrong schema. This is not fixed yet and the metalink notes states that 10.2 is more vulnerable than 10.1. Read it and take precautions if you are on 10g.