Call: +44 (0)1904 557620 Call

Pete Finnigan's Oracle Security Weblog

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

[Previous entry: "database security bloopers"] [Next entry: "A new Oracle security scanner written in Ruby"]

Apex and its security model

Gary has posted a very interesting article about APEX and the use of DBMS_SYS_SQL titled "Database 11g and Apex by default". This is a good post, i wanted to make a comment on Gary's blog but to do so meant registering with blogger/Google which I dont want to do so my comment is here:

"Thanks for a very interesting post. I think there are issues with this model and recent CPUs with lots of remote exploits/bugs in Apex that dont need authentication clearly confirms this. I agree with you its crazy to enable Apex by default in 11g, lets see if they do. This would feed into the ever increasing array of features enabled by default.."