<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
   <channel>
      <title>The Oracle Global Product Security Blog</title>
      <link>http://blogs.oracle.com/security/</link>
      <description></description>
      <language>en</language>
      <copyright>Copyright 2008</copyright>
      <lastBuildDate>Mon, 04 Aug 2008 12:04:06 -0800</lastBuildDate>
      <generator>http://www.sixapart.com/movabletype/</generator>
      <docs>http://blogs.law.harvard.edu/tech/rss</docs> 

            <item>
         <title>Updated Security Alert for CVE-2008-3257 Issued</title>
         <description><![CDATA[<p>Hi, this is Eric Maurice again.</p>

<p>Oracle today issued an updated <a href="http://www.oracle.com/technology/deploy/security/alerts/alert_cve2008-3257.html">Security Alert</a> related to the <a href="http://blogs.oracle.com/security/2008/07/security_alert_for_cve-2008-3257_released.html">previously reported vulnerability CVE-2008-3257</a>.  The purpose of this updated Security Alert is to let WebLogic customers know about the immediate availability of the fixes on all supported platform and version combinations.  </p>

<p>As we reported a week ago, Oracle felt that the nature of this vulnerability, which affected the Apache plugin for Oracle WebLogic, along with its publication in various public forums, and the availability of exploit code, warranted the issuance of an out-of-cycle patch.  While this patch will also be included in the upcoming <a href="http://www.oracle.com/technology/deploy/security/alerts.htm">Critical Patch Update </a>(scheduled for October 14, 2008), we recommend that customers apply the current patch as soon as possible, even if they have implemented the <a href="https://support.bea.com/application_content/product_portlets/securityadvisories/2793.html">recommended workarounds</a>.</p>

<p><br />
<u>For More Information:</u></p>

<p>The Security Alert for this vulnerability is posted on <a href="http://www.oracle.com/technology/deploy/security/alerts/alert_cve2008-3257.html ">http://www.oracle.com/technology/deploy/security/alerts/alert_cve2008-3257.html </a></p>

<p>Oracle Software Security Assurance web site is located at: <a href="http://www.oracle.com/security/software-security-assurance.html ">http://www.oracle.com/security/software-security-assurance.html </a>   </p>

<p>Critical Patch Updates & Security Alerts web site is located at: <a href="http://www.oracle.com/technology/deploy/security/alerts.htm ">http://www.oracle.com/technology/deploy/security/alerts.htm </a><br />
</p>]]></description>
         <link>http://blogs.oracle.com/security/2008/08/updated_security_alert_for_cve.html</link>
         <guid>http://blogs.oracle.com/security/2008/08/updated_security_alert_for_cve.html</guid>
        
        
         <pubDate>Mon, 04 Aug 2008 12:04:06 -0800</pubDate>
      </item>
            <item>
         <title>Security Alert for CVE-2008-3257 Released</title>
         <description><![CDATA[<p>Hi, this is Eric Maurice.</p>

<p>Oracle today issued a Security Alert for a vulnerability affecting the Apache plugin for Oracle WebLogic (formerly BEA WebLogic).  It is the first Security Alert since the introduction of the <a href="http://www.oracle.com/technology/deploy/security/alerts.htm">Critical Patch Update</a> process in January 2005.  Issuing this alert was required because the vulnerability and associated exploit codes have been posted in various public forums.  This vulnerability has received the CVE identifier <a href="http://www.oracle.com/technology/deploy/security/alerts/alert_cve2008-3257.html">CVE-2008-3257</a>.  The CVSS score for this vulnerability is 10.0.  It is remotely exploitable without authentication (i.e. it may be exploited over the network without the need for a username and password), and it can result in compromising the confidentiality, integrity, and availability of the targeted system.</p>

<p>When Oracle became aware of this issue, our security and development teams worked diligently to develop an effective workaround to prevent a successful exploitation of the vulnerability.  Detailed instructions for this workaround have been posted on the <a href="https://support.bea.com/application_content/product_portlets/securityadvisories/2793.html">eSupport site</a>, and Oracle has already issued a <a href="http://www.oracle.com/technology/deploy/security/alerts/alert_cve2008-3257.html">Security Alert </a>to all WebLogic customers to let them know about this workaround.  In addition, Oracle will also issue an out-of-cycle security patch for this vulnerability as soon as the fix has been produced for all supported version-platform combinations.  We expect this fix to be ready very soon, and we will issue an updated Security Alert to let customers know about its availability.  <em>In the meanwhile, we recommend that all customers implement the <a href="https://support.bea.com/application_content/product_portlets/securityadvisories/2793.html">recommended workaround</a>.</em></p>

<p>Unfortunately, the person(s) who published this vulnerability and associated exploit codes did not contact Oracle before publicly disclosing this issue.  This means that the vulnerability was made public before providing Oracle an opportunity to develop an appropriate fix for this issue and notify its customers.  In addition, the vulnerability was made public shortly after the publication of the July 15th Critical Patch Update, therefore prompting Oracle to issue an out of cycle security update.  </p>

<p><br />
<u>For More Information:</u></p>

<p>Workaround instructions are posted on <a href="https://support.bea.com/application_content/product_portlets/securityadvisories/2793.html">https://support.bea.com/application_content/product_portlets/securityadvisories/2793.html</a></p>

<p>The Security Alert for this vulnerability is posted on <a href="http://www.oracle.com/technology/deploy/security/alerts/alert_cve2008-3257.html">http://www.oracle.com/technology/deploy/security/alerts/alert_cve2008-3257.html</a></p>

<p>Oracle Software Security Assurance web site is located at: <a href="http://www.oracle.com/security/software-security-assurance.html ">http://www.oracle.com/security/software-security-assurance.html </a></p>

<p>Critical Patch Updates & Security Alerts web site is located at: <a href="http://www.oracle.com/technology/deploy/security/alerts.htm">http://www.oracle.com/technology/deploy/security/alerts.htm</a></p>]]></description>
         <link>http://blogs.oracle.com/security/2008/07/security_alert_for_cve-2008-3257_released.html</link>
         <guid>http://blogs.oracle.com/security/2008/07/security_alert_for_cve-2008-3257_released.html</guid>
        
        
         <pubDate>Mon, 28 Jul 2008 11:44:35 -0800</pubDate>
      </item>
            <item>
         <title>July 2008 Critical Patch Update Released </title>
         <description><![CDATA[<p>Hello, this is Eric Maurice again!  </p>

<p>Oracle today released the July 2008 Critical Patch Update (<a href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html">CPUJul2008</a>).  While this is Oracle’s fifteenth Critical Patch Update (CPU), and personally, my ninth CPU (I joined Oracle in time for <a href="http://blogs.oracle.com/security/2006/07/">CPUJul2006</a>), I am still impressed with the dedication and great talent of everyone who is involved with the production of each CPU.  Over the years, Oracle has introduced many enhancements to the CPU and successfully extended its scope to many products added via acquisition.  </p>

<p>Today’s CPU is characterized by two significant developments: the adoption of the <a href="http://cve.mitre.org/">Common Vulnerabilities and Exposure</a> (CVE) numbering scheme, and the inclusion of the <a href="http://www.bea.com">BEA</a>, <a href="http://www.oracle.com/timesten/index.html">TimesTen</a>, and <a href="http://www.oracle.com/hyperion/index.html">Hyperion </a>product lines in the <a href="http://www.oracle.com/security/software-security-assurance.html">Critical Patch Update</a>.  But more on these topics later!  Let’s first have a look at the content of this CPU.</p>

<p>Today’s CPU include fixes for 45 new security vulnerabilities across a wide range of products: Oracle Database Server, Oracle Application Server (including Hyperion Peformance Suite), Oracle TimesTen, Oracle Enteprise Manager, Oracle EBusiness Suite, Oracle PeopleSoft Enterprise, and Oracle WebLogic Server.  Eleven of these vulnerabilies affect Oracle Database Server, and none of these Database Server vulnerabilities are remotely exploitable without authentication.  The criticality for these 45 new vulnerabilities fixed in the CPU range between the CVSS base scores of 1.5 to 6.8 (on a scale of 10).  See <a href="http://blogs.oracle.com/security/2007/11/understanding_the_common_vulne_1.html">our previous blog entry series </a>for more information about CVSS and an explanation of the CVSS base scoring formula.  Finally note that none of these 45 fixes affect client-only installations.</p>

<p>As mentioned earlier in this blog, this CPU is also characterized by the adoption of the <a href="http://cve.mitre.org/">Common Vulnerabilities and Exposure</a> (CVE) system.  As explained on the <a href="http://cve.mitre.org/cve/identifiers/index.html">CVE program web site</a>, “<em>CVE Identifiers (also called "CVE-IDs," "CVE names," "CVE numbers," and "CVEs") are unique, common identifiers for publicly known information security vulnerabilities</em>.”  Starting with the July 2008 Critical Patch Update, Oracle will use these CVE identifiers to identify the vulnerabilities fixed in each new CPU, and will no longer use the proprietary numbering convention that was previously used in the CPU risk matrices.  As a result, each new vulnerability fixed in the CPU will be assigned a unique CVE Identifier.  This change was made possible because Oracle became a “<em>Candidate Naming Authority</em>” under the CVE program.  Note that while the CPU documentation is the only authoritative source of information about vulnerabilities in Oracle products, and as such should remain the primary source of information about such vulnerabilities, the use of unique CVE identifiers should result in simplifying how Oracle vulnerabilities are identified in external security reports such as those produced by security researchers and vulnerability management systems.  The use in the CPU documentation of CVE identifiers, along with the publication of the Common Vulnerability Scoring System (CVSS) base scores, is further evidence of Oracle’s customer focus in its vulnerability disclosure practices.</p>

<p>Finally, this Critical Patch Update also marks the inclusion of the BEA, TimesTen, and Hyperion product lines in the CPU process.  </p>

<p>The inclusion of BEA in the CPU was particularly rapid because of the similarities that existed between the current CPU process at Oracle and the patching procedures previously in use at BEA.  Furthermore, all involved in the CPU process have grown skilled with dealing with newly acquired companies, products (and people).  The skillset with which Oracle successfully integrates acquisitions extends to all involved with <a href="http://www.oracle.com/security/software-security-assurance.html">Oracle Software Security Assurance</a>.  </p>

<p>Today, the CPU process provides a cohesive program for the patching of hundreds of Oracle products across many various platforms.  Developed with customers in mind, the Critical Patch Update provides a predictable patching schedule that is designed to fall outside of typical blackout dates experienced by most customers (such as end of fiscal year, end of calendar year, etc.)  As a result of this predictability (CPUs are issued on the Tuesday closest to the 15th of the months of January, April, July, and October), Oracle customers can leverage normal maintenance windows for deploying security updates to Oracle products, thus reducing interruptions to their production environment.  </p>

<p><u>For More Information:</u></p>

<p>Oracle Software Security Assurance web site is located at: <a href="http://www.oracle.com/security/software-security-assurance.html">http://www.oracle.com/security/software-security-assurance.html</a></p>

<p>Critical Patch Updates & Security Alerts web site is located at: <a href="http://www.oracle.com/technology/deploy/security/alerts.htm ">http://www.oracle.com/technology/deploy/security/alerts.htm </a></p>

<p>The CVE web site is located at: <a href="http://cve.mitre.org/ ">http://cve.mitre.org/ </a></p>]]></description>
         <link>http://blogs.oracle.com/security/2008/07/july_2008_critical_patch_updat.html</link>
         <guid>http://blogs.oracle.com/security/2008/07/july_2008_critical_patch_updat.html</guid>
        
        
         <pubDate>Tue, 15 Jul 2008 12:01:04 -0800</pubDate>
      </item>
            <item>
         <title>IOUG Security Survey </title>
         <description><![CDATA[<p>Hi, this is Eric Maurice again.</p>

<p>The greatest external factor influencing <a href="http://www.oracle.com/security/software-security-assurance.html">Oracle Software Security Assurance </a>is the feedback we receive from customers.  While members of Oracle’s Global Product Security team have daily interactions with customers, security researchers, or industry analysts, the most exhaustive channel for customer feedback is the Security Customer Advisory Council that is being managed by the Program Management Office of the Global Product Security organization.   </p>

<p>The Security Customer Advisory Council (SCAC for short) is comprised of customers from around the world and representing various industries.  Moreover, SCAC members are collectively using most if not all Oracle products.  The SCAC meets at least once a year to discuss emerging security topics, Oracle’s security strategy, and Oracle Software Security Assurance programs, including the Critical Patch Update and related activities.  For example, the recommendations of the SCAC have previously led Oracle to adopt the <a href="http://blogs.oracle.com/security/2007/11/02#a157">Common Vulnerability Scoring System </a>(CVSS) as a standard way to rate the severity of the vulnerabilities fixed in the CPU and to issue pre-release CPU announcements (these are issued on the <a href="http://www.oracle.com/technology/deploy/security/alerts.htm">Critical Patch Updates and Security Alerts page</a> the Thursday before the CPU due date).</p>

<p>Most recently, the <a href="http://www.ioug.org/">Independent Oracle User Group </a>(IOUG) joined the Security Customer Advisory Council.  This initiative was launched by the <a href="http://enterprisesig.oracle.ioug.org/">Enterprise Best Practices SIG</a> under the leadership of Michelle Malcher, the SIG president.  As a component to this initiative, Oracle and IOUG also produced a number of security training webcasts.  These webcasts are available online on the <a href="http://ioug.itconvergence.com/pls/apex/f?p=201:8:2776296981592341::NO">Enterprise Best Practices SIG Download Page</a>.  The two most recent webcasts were particularly popular!  In March, Daniel Wong (Director of Engineering the Database Security group) presented the <a href="http://ioug.itconvergence.com/pls/apex/ESIG.download_my_file?p_file=464.">security enhancements in Oracle Database Server 11g</a>.  Last month, Jenny Tsai-Smith (Senior Director in Curriculum Development) and Mark Fallon (Director of Software Development) recorded a <a href="http://www.ioug.org/networking/SIGs/Archived_SIG_Webcasts.cfm">webcast on how to best prevent SQL Injection attacks</a>.</p>

<p>In preparation for the next Security Customer Advisory Council (to be held in October), the Enterprise Best Practices SIG of IOUG posted a <a href="http://survey.ioug.org/">security survey</a> to try to gather information about the current security practices of its members, particularly around the application of the Critical Patch Updates and Patch Sets and to gather recommendations from members about possible process improvements that Oracle could bring to further enhance Oracle Software Security Assurance activities.  Michelle and I recorded a <a href="http://www.ioug.org/networking/SIGs/SurveyPodcastrev.mp3">webcast </a>that discuss the objectives of the survey.  We went through two iterations of the survey, further fine-tuning it, to come up with a shorter, simpler survey, that drill down to areas that are most likely to yield feedback from Oracle users (the current survey is titled “OSSA Security Survey II” on the IOUG web site).  </p>

<p>We would like to encourage all Oracle users to take this survey!!! (Remember to select “OSSA Security Survey II”).  A <a href="https://www.ioug.org/secure/membership/index.cfm?requestedMemberType=AM">Free Associate Membership to IOUG </a>may be required to take the survey, but completing this form should take no more than five minutes.  Completing the survey itself should take no more that ten minutes (unless you decide to take advantage of the free form question at the end of the survey by writing an extensive set of recommendations for Oracle).</p>

<p><u>Information about the Security Survey:</u><br />
The survey is located at <a href="http://survey.ioug.org">http://survey.ioug.org</a> . (Please select “OSSA Survey II”.)<br />
The webcast explaining the objectives of the survey is located at: <a href="http://www.ioug.org/networking/SIGs/SurveyPodcastrev.mp3 ">http://www.ioug.org/networking/SIGs/SurveyPodcastrev.mp3 </a></p>

<p><u>Information about Oracle Software Security Assurance:</u><br />
For more information about the Security Customer Advisory Council, you can e-mail: <a href="mailto:securityCAC_ww@ORACLE.COM">securityCAC_ww@ORACLE.COM</a> </p>

<p><u>Information about IOUG:</u><br />
IOUG web site is located at <a href="http://www.ioug.org">http://www.ioug.org</a>. <br />
For information about IOUG membership, see the IOUG membership page.<br />
Recorded IOUG webcasts can be found at <a href="http://www.ioug.org/networking/SIGs/Archived_SIG_Webcasts.cfm">http://www.ioug.org/networking/SIGs/Archived_SIG_Webcasts.cfm</a></p>

<p></p>

<p></p>

<p></p>

<p><br />
</p>]]></description>
         <link>http://blogs.oracle.com/security/2008/07/ioug_security_survey_.html</link>
         <guid>http://blogs.oracle.com/security/2008/07/ioug_security_survey_.html</guid>
        
        
         <pubDate>Tue, 08 Jul 2008 11:26:27 -0800</pubDate>
      </item>
            <item>
         <title>Sensitive information - is it really secret?</title>
         <description><![CDATA[<p><P class=MsoNormal style="MARGIN: 0in 0in 0pt">This is John Heimann, Sr. Director, Oracle Global Product Security (GPS), again.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>In my role as manager of the GPS Security Program Management team, one of my primary concerns is ensuring that Oracle�s products effectively protect sensitive customer data. <SPAN style="mso-spacerun: yes">&nbsp;</SPAN>More specifically, the Security Program Management team helps to ensure that Oracle product development groups consistently apply secure coding standards, tools and processes that help reduce the likelihood of exploitable security vulnerabilities in our products.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Oracle product development groups have designed and implemented many security features that customers can use to protect sensitive information.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>My team works with product groups to help ensure that Oracle developers avoid security flaws that could allow attackers to bypass these security features and gain access to sensitive data.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">In recent years, there have been a number of high profile breaches of information systems that process sensitive information associated with thousands or even millions of <A href="http://www.privacyrights.org/">people</A>. When Oracle GPS becomes aware of breaches of information systems processing sensitive data, we typically investigate the causes of the breaches.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Even if the breached information system did not include any Oracle technology, analyzing root causes of a breach can allow us to help improve the design of our products, avoid certain classes of vulnerabilities, or improve the security guidance we offer to customers.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">There are cases where understanding why a serious data breach was so serious require extending the breach analysis beyond the boundary of the information system. In those cases, the analysis includes how the people and systems outside the breached system use the information that was revealed.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Sometimes, the analysis indicates that certain categories of data considered �sensitive� or �private� when they were defined - often in a pre-internet, or even pre-computer, era - are now used in ways that are fundamentally insecure.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The fact that those types of data are now processed by internetworked computer systems simply highlights that insecurity, and makes exploitation of it easier.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-spacerun: yes"></SPAN>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-spacerun: yes"></SPAN>As a concrete example, suppose I told you that you are required to use a system that is responsible for managing your personal identity, tax history, past credit records, ability to get future credit, and other important functions in your daily life.&nbsp; You will be issued a unique password to access that system, and you can NEVER change it.&nbsp;&nbsp; Contrary to typical password best practices, the password has well-known internal <A href="http://www.socialsecurity.gov/history/ssn/geocard.html">structure</A> that may make components of it predictable. Moreover, you are required to give that password to banks, credit companies, utilities, the US Internal Revenue Service and other government agencies, tax preparers and accountants, and every employer you have ever worked for.&nbsp; Would you agree to use such a system?&nbsp;&nbsp; You probably would not, but that's exactly what we in the US are required to do with our social security numbers (SSNs).&nbsp; We pretend that SSNs are "private" information but given the number of people to whom we disclose SSNs, they should not be considered private.<BR><BR>A similar situation exists with credit card numbers. If I know your credit card number and date of card expiration, I can make purchases by phone or on the Internet that will be charged to your credit card account. You can change a credit card number on a time scale of months or years - by canceling the card and applying for a new one - but on a short term time scale a credit card number is effectively fixed and unchangeable, and you have to reveal it to hundreds of people and computer systems every month.&nbsp; How would anyone possibly consider that information "secret?�&nbsp; Note that credit cards now have three digit Card Security Codes (CSCs) printed on the back to protect against fraudulent use of credit card numbers.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Merchants often ask for a CSC when a customer does not present a physical card during a purchase (e.g., when ordering something by phone or on the internet).<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Since the CSC number is fixed for the life of a card, can be obtained by any merchant who handles a customer�s physical card, and must be disclosed any time a customer makes an internet or phone purchase, it can�t be considered truly secret either.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>We pretend that SSNs and or credit card numbers are �private� or �secret� and have to be protected by elaborate computer security mechanisms, but in fact they have never been truly secret.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">The real problem is that our social systems associated with identity and credit allow an attacker with simple knowledge of Joe Blow's SSN or credit card number to masquerade as Joe Blow and perform some privileged function, like making a purchase on Joe's account.&nbsp; Computers make attacks that were already in existence (like dumpster diving for credit card slips with card numbers, or paystubs with SSNs) much easier, and simply underscore the weakness in the greater system that handles the information, including people and processes as well as computers.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">At one point in time, when credit card or SSN data were disclosed to a limited number of human users through manual processes, simply demonstrating knowledge of an SSN or credit card number may have been an acceptably secure means of authentication.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Unfortunately for those of us who still must use SSNs and credit cards, simple knowledge of SSN or credit card number cannot now be considered a secure means of user authentication.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>In fact, such practice violates several basic, generally accepted principals for secure authentication.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Among these principals are</P><br />
<UL dir=ltr style="MARGIN-RIGHT: 0px"><br />
<LI><br />
<DIV class=MsoNormal style="MARGIN: 0in 0in 0pt">data used for authentication purposes must not be widely shared or stored in multiple places</DIV></LI><br />
<LI><br />
<DIV class=MsoNormal style="MARGIN: 0in 0in 0pt">authentication data should not be difficult or impossible to change</DIV></LI><br />
<LI><br />
<DIV class=MsoNormal style="MARGIN: 0in 0in 0pt">authentication is much more secure when it involves something you have, or something you are, in addition to something you know.</DIV></LI></UL><br />
<P class=MsoNormal dir=ltr style="MARGIN: 0in 0in 0pt">Note that the weaknesses associated with SSNs and credit card numbers have been recognized for many years, and in the case of payment card information were one of the reasons for the creation of the Secure Electronic Transcation (SET) protocol in 1996.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The SET protocol never became established because in the late 1990s, the rate of fraud associated with the existing process (simply giving your credit card number to a merchant) didn't justify the added expense and overhead of using SET.&nbsp; I suspect that over time, as more fraud associated with phone or online credit card sales occurs, people will re-examine the basic problem associated with using static credit card information and consider more sophisticated mechanisms for user authentication in payment transactions.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Similarly, as identity theft becomes more common, I expect we will start to see a more complex mechanism than simple knowledge of a permanent SSN to evolve for authenticating users to potential payees.</P><br />
<P class=MsoNormal dir=ltr style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">Preventing exploitation of information by improving the security of computer systems in which that information is managed is not enough!<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>In many cases, the information itself, and/or how it is used in social processes that include but are not limited to computer systems, needs to change before that information can be used securely.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Properly planning and documenting business processes, including the definition of the information being maintained in the organization and defining what constitutes appropriate use of the information is required as a pre-requisite to defining a sound IT security strategy.</P></p>]]></description>
         <link>http://blogs.oracle.com/security/2008/06/sensitve_information_is_it_rea.html</link>
         <guid>http://blogs.oracle.com/security/2008/06/sensitve_information_is_it_rea.html</guid>
        
        
         <pubDate>Wed, 04 Jun 2008 12:55:51 -0800</pubDate>
      </item>
            <item>
         <title>SQL Injections, Lateral or Not</title>
         <description><![CDATA[<p>Hi, this is Eric Maurice again.</p>

<p>A number of publications recently reported about a <A href="http://www.pcworld.com/businesscenter/article/145101/researcher_finds_new_way_to_hack_oracle_database.html"><FONT color=red>new way to hack Oracle databases</FONT></A>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>These articles were in fact referring to a recently published paper by David Litchfield, titled <A href="http://www.databasesecurity.com/dbsec/lateral-sql-injection.pdf"><FONT color=red>Lateral SQL Injection: A New Class of Vulnerability in Oracle</FONT></A>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></p>

<p><A href="http://en.wikipedia.org/wiki/SQL_injection"><FONT color=red>SQL Injections</FONT></A> are a very well known class of attacks, which can affect virtually any relational databases when no or insufficient input validation has been implemented.</p>

<p>In simple terms, SQL Injection attacks are designed to leverage improper coding of database-powered applications that, in the absence of proper input validation, allow a malicious attacker to insert string input to an application.  In such scenario, an attacker can "inject" or pass on harmful SQL commands, which will then be executed by the back-end database.  The consequences of successful SQL Injections can be severe: an attacker could gain access to sensitive data, manipulate database information, and in some instances, change the structure of the database, deny legitimate access to it, or grant unauthorized privileges to himself or to others.  Web applications are particularly at risk because -- exposed to the Internet -- they often allow an attacker to perpetrate SQL injection attacks without being authenticated to the targeted database or application.</p>

<p>An important aspect of <A href="http://www.oracle.com/security/software-security-assurance.html"><FONT color=red>Oracle Software Security Assurance</FONT></A> is sharing security information and recommended practices with customers so that they can optimize their security posture.  We recently posted a <A href="http://st-curriculum.oracle.com/tutorial/SQLInjection/index.htm"><FONT color=red>SQL Injection tutorial online</FONT></A> that demonstrates how to properly implement input validation controls and prevent this kind of attacks.</p>

<p>In his paper, David explains that in certain circumstances, SQL Injections can also take place in procedures that are not intended to take user input.  Note however, that in such a scenario, setting up the attack requires that the attacker had been previously granted a database account with necessary privileges.  David concludes that it is doubtful that this kind of attacks becomes:<I>exploitable in the normal sense</I>.</p>

<p>While some may consider the topic of Lateral SQL Injections as mostly academic, and relevant only for the security researchers community, I think this paper has the merit of further raising the awareness of database administrators and programmers to SQL Injections.  SANS and others have flagged this class of attacks as a primary threat for database-driven sites and applications. <em>In my opinion, proper input validation constitutes a required security practice that needs to be extended to all functions and procedures, whether they are expected or not to take user input.  Furthermore, as expressed in the SQL Injection training and in the Oracle documentation, bind variables should be used as much as possible.</em></p>

<p>As discussed above, SQL injection happens when a dynamic SQL statement is constructed from user input.  In the case of the attack discussed in David's paper, the dynamic SQL statement is being constructed from data stored in the database.  The values are then being converted into character strings based on a template provided by the system.  It is this template, as opposed to the stored value, that controls what will be injected.</p>

<p>When bind variables are properly used, the bind variable name is physically part of the SQL statement, but this bind variable is used as a reference to the rendered value.  As a result, the rendered value is never interpreted directly as part of the SQL statement; therefore no SQL Injection can take place.</p>

<p>In some instances, like DDL operations where a database object needs to be constructed, Oracle administrators do not have the option of using a bind variable. In this instance, the DBMS_ASSERT package should be used to correctly handle the rendered value, either ENQUOTE_LITERAL when it is going to be used as a literal or ENQUOTE_NAME when it is going to be used as the name of a SQL object.</p>

<p>For more information, see the <A href="http://st-curriculum.oracle.com/tutorial/SQLInjection/index.htm"><FONT color=red>online tutorial Defending Against SQL Injection Attacks</FONT></A>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Information on <A href="http://www.oracle.com/security/software-security-assurance.html"><FONT color=red>Oracle Software Security Assurance</FONT></A> is available on <A href="http://www.oracle.com/security/"><FONT color=red>Oracle.com</FONT></A>.<SPAN style="mso-spacerun: yes">&nbsp; </p>]]></description>
         <link>http://blogs.oracle.com/security/2008/04/sql_injections_lateral_or_not_1.html</link>
         <guid>http://blogs.oracle.com/security/2008/04/sql_injections_lateral_or_not_1.html</guid>
        
        
         <pubDate>Mon, 28 Apr 2008 14:20:23 -0800</pubDate>
      </item>
            <item>
         <title>April 2008 Critical Patch Update Released</title>
         <description><![CDATA[<p><P class=MsoNormal style="MARGIN: 0in 0in 0pt">Hello, this is Eric Maurice!<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">Oracle today released the April 2008 Critical Patch Update (<A href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2008.html"><B><FONT color=red>CPUApr2008</FONT></B></A>).<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This Critical Patch Update (CPU) addresses a total of 41 vulnerabilities affecting Oracle Database Server, Oracle Application Express, Oracle Application Server, Oracle E-Business Suite, Oracle Enterprise Manager, Oracle PeopleSoft Enterprise, and Oracle Siebel CRM Applications.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Fifteen of these vulnerabilities are specific to Oracle Database Server (an additional two affects Application Express).<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Note however that a number of these Database Server vulnerabilities affect optional Database Server components, and only one of these Database Server vulnerabilities can be remotely exploitable without authentication. </P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">While none of the Oracle Database Server fixes requires patching the database client-only installations, this CPU includes one fix for Oracle Application Server client-only installations.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>As with the previously released <A href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2008.html"><B><FONT color=#ff0000>January 2008 CPU</FONT></B></A>, this CPU includes an Application Server client fix to address a vulnerability affecting <A href="http://www.oracle.com/technology/software/products/developer/htdocs/jinit.htm"><B><FONT color=#ff0000>JInitiator</FONT></B></A>, a web browser extension that enables end users to run Oracle Forms Services applications within their browser.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN><I>This vulnerability only affects version 1.3.1.14 and earlier versions of JInitiator</I>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Just like the previously fixed JInitiator vulnerabilities, this vulnerability has a CVSS score of 9.3 because it could allow an attacker to gain full control of the targeted <I>client</I> (e.g. workstation) at the Operating System level, but it cannot result in a compromise of the <I>server</I> component.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">This fourteenth CPU also marks another milestone!<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>For the first time, the CPU includes fixes for Oracle�s Siebel CRM Applications.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>As a matter of policy, Oracle tries to synchronize the release of the security patches of acquired product lines with the CPUs, and ultimately ensure that new product lines join the CPU process (in the way that PeopleSoft, JD Edwards, and now Siebel have).<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">The CPU fixes for Siebel CRM Applications will be <I>cumulative</I> for the product line in which they apply (There are currently four supported product lines).<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This will allow customers who have previously skipped security patches to quickly catch up by applying the most current CPU.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">The inclusion of Siebel Enterprise products in the CPU process provides former Siebel customers with a number of benefits.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Under the Siebel model, security fixes were typically included, along with non-security fixes, in the �Fix Packs�.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The most significant vulnerabilities could also be fixed with dedicated ad hoc (unscheduled and non-cumulative) fixes.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The inclusion of Siebel Enterprise products in the CPU process therefore provides customers enhanced visibility to security fixes.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>In addition, customers benefit from the predictability of the CPU schedule, thus potentially reducing the cost of security management in their environment.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">The <A href="http://www.oracle.com/technology/deploy/security/alerts.htm"><STRONG><FONT color=red>Critical Patch Updates and Security Alerts page</FONT></STRONG></A> on <A href="http://www.oracle.com/technology/index.html"><STRONG><FONT color=#ff0000>Oracle Technology Network</FONT></STRONG></A> provides detailed information about this CPU, as well as previous CPUs and Security Alerts.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Oracle Technology Network also hosts additional information about <A href="http://www.oracle.com/technology/deploy/security/cpu/cvssscoringsystem.htm"><B><FONT color=red>Oracle�s implementation of the CVSS 2.0 standard</FONT></B></A> and a <A href="http://www.oracle.com/technology/deploy/security/cpu/advisorymatrixglossary.htm"><B><FONT color=red>glossary of the terms used in the Risk Matrices in the CPU Advisory</FONT></B></A>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The<FONT color=red> </FONT><A href="http://www.oracle.com/security/resource-library.html"><STRONG><FONT color=red>Resource Library</FONT></STRONG></A> on the <A href="http://www.oracle.com/security/software-security-assurance.html"><STRONG><FONT color=red>Oracle Software Security Assurance web site</FONT></STRONG></A> also provides a number of links to useful security resources.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P></p>]]></description>
         <link>http://blogs.oracle.com/security/2008/04/april_2008_critical_patch_upda.html</link>
         <guid>http://blogs.oracle.com/security/2008/04/april_2008_critical_patch_upda.html</guid>
        
        
         <pubDate>Tue, 15 Apr 2008 14:57:06 -0800</pubDate>
      </item>
            <item>
         <title>Podcast Interview of Mary Ann Davidson Now Available Online</title>
         <description><![CDATA[<p><P class=MsoNormal style="MARGIN: 0in 0in 0pt">Hi, this is Eric Maurice!<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This very short blog to let you know about recently recorded podcasts and webcasts on <A href="http://www.oracle.com/security/software-security-assurance.html"><FONT color=red>Oracle Software Security Assurance</FONT></A> topics.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">We recently recorded a <A href="http://feeds.feedburner.com/~r/OracleDatabaseInsider/~3/264066038/6402270_Mary_Ann_Davidson_040408.mp3"><FONT color=red>podcast interview with Oracle CSO, Mary Ann Davidson</FONT></A>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>In this podcast, Mary Ann discusses the importance of Oracle Software Security Assurance, the role of Oracle�s Global Product Security Group, and some of the changes that were introduced with the Critical Patch Update.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-spacerun: yes"></SPAN>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">Oracle and the <A href="http://enterprisesig.oracle.ioug.org/"><FONT color=red>Enterprise Best Practices Special Interest Group (SIG)</FONT></A> of the <A href="http://www.ioug.org/"><FONT color=red>Independent Oracle User Group</FONT></A> recently delivered a <A href="http://ioug.itconvergence.com/pls/apex/ESIG.download_my_file?p_file=464"><FONT color=red>one hour webcast introducing Oracle�s secure configuration initiative and discussing the security enhancements in Oracle Database 11g</FONT></A>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>In this webcast, Daniel Wong, Director of Engineering for Database Security at Oracle, discusses in technical detail the security changes introduced in the default configuration of Oracle Database Server with 11g.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Such changes affect the default audit settings, authentication and password management, and access control changes to certain UTL packages, etc.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Daniel then provides security recommendations for customers who are looking at upgrading (or have upgraded to) Oracle Database 11g.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>A <A href="http://www.ioug.org/networking/SIGs/Archived_Webcasts/2007-07-25_Recommendations_for_Securely_Configuring_Oracle_Databases.wmv"><FONT color=red>previously recorded webcast providing technical recommendations for securely configuring Oracle databases</FONT></A> is also available on the<FONT color=red> </FONT><A href="http://ioug.itconvergence.com/pls/apex/f?p=201:8:1871541109612319::NO"><FONT color=red>IOUG website under the archived SIG webcasts section</FONT></A><FONT color=red>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT color=red><SPAN style="mso-spacerun: yes"></SPAN></FONT>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">Note that a <A href="http://www.ioug.org/about/join.cfm"><FONT color=red>registration to IOUG�s web site</FONT></A> may be required to access some of this content (FREE membership to the Enterprise Best Practices SIG is also available <A href="http://ioug.itconvergence.com/pls/apex/f?p=201:1:1581316554439860::NO:::"><FONT color=red>here</FONT></A>).</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><U><FONT face=Geneva,Arial,Sans-Serif size=2>For more information:</FONT></U></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif size=2>Mary Ann Davidson�s interview is available </FONT><A href="http://www.oracle.com/database/podcasts.html"><FONT face=Geneva,Arial,Sans-Serif color=red size=2>here</FONT></A><FONT face=Geneva,Arial,Sans-Serif size=2>.</FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif size=2>IOUG�s webcast on Oracle Database 11g security is available </FONT><A href="http://ioug.itconvergence.com/pls/apex/ESIG.download_my_file?p_file=464"><FONT face=Geneva,Arial,Sans-Serif color=red size=2>here</FONT></A><FONT face=Geneva,Arial,Sans-Serif size=2>.</FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif size=2>IOUG�s webcast on securely configuring Oracle databases is available </FONT><A href="http://www.ioug.org/networking/SIGs/Archived_Webcasts/2007-09-26_Recommendations_For_Securing_Oracle_Application_Server.wmv"><FONT face=Geneva,Arial,Sans-Serif color=red size=2>here</FONT></A><FONT face=Geneva,Arial,Sans-Serif size=2>.</FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif size=2>Oracle Software Security Assurance Resource Library is available </FONT><A href="http://www.oracle.com/security/resource-library.html"><FONT face=Geneva,Arial,Sans-Serif color=red size=2>here</FONT></A><FONT face=Geneva,Arial,Sans-Serif size=2>.</FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif size=2>The download page for IOUG�s Enterprise Best Practices SIG is available </FONT><A href="http://ioug.itconvergence.com/pls/apex/f?p=201:8:1871541109612319::NO"><FONT face=Geneva,Arial,Sans-Serif color=red size=2>here</FONT></A><FONT face=Geneva,Arial,Sans-Serif size=2>.</FONT></P></p>]]></description>
         <link>http://blogs.oracle.com/security/2008/04/podcast_interview_of_mary_ann.html</link>
         <guid>http://blogs.oracle.com/security/2008/04/podcast_interview_of_mary_ann.html</guid>
        
        
         <pubDate>Fri, 04 Apr 2008 14:17:33 -0800</pubDate>
      </item>
            <item>
         <title>Oracle and Security Evaluations</title>
         <description><![CDATA[<p><P class=MsoNormal style="MARGIN: 0in 0in 0pt">Hello, I'm Petra Manche!<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>I work in the Security Evaluations team in Oracle's Security Assurance Group.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Security Evaluations are a critical part of <A href="http://www.oracle.com/security/software-security-assurance.html"><FONT color=red>Oracle Software Security Assurance</FONT></A>, and my team is responsible for managing the <A href="http://www.oracle.com/security/external-security-evaluations.html"><FONT color=red>independent security evaluations</FONT></A> of all Oracle products</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">Oracle recently completed the evaluations of Oracle Database 10g Release 2 (10.2.0.3) and Oracle Label Security 10g Release 2 (10.2.0.3) against <I>Common Criteria assurance level EAL4+</I> and against the <I>U.S. Government Protection Profile for Database Management Systems in Basic Robustness Environments (Version 2.1)</I>.&nbsp;&nbsp; As usual Oracle evaluated the Enterprise Edition of the Database, but for the first time we also evaluated Standard Edition and Standard Edition 1.&nbsp; Real Application Clusters (RAC), Enterprise Users, and Partitioning were also included with these evaluations for the first time.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt"></SPAN>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt">For those who don't know what Security Evaluations are: independent bodies (laboratories) examine Information Technology products and systems, and if the examination is passed, a certificate is awarded (usually by a government body).<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This process provides confidence in the security of the Evaluated products to end users, including government and military institutions.</SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt"><SPAN style="mso-spacerun: yes"></SPAN></SPAN>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt">Oracle has a long history among IT vendors of having security evaluations performed on its products.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Since committing to the security evaluation process in 1990, Oracle has successfully completed 29 security evaluations.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Many of the early evaluations were on Oracle Database Server, but more recently we have extended our scope and evaluated other products including Oracle Enterprise Linux, Oracle Application Server and Oracle Internet Directory.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt"></SPAN>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt">Oracle is currently committed to evaluating its products under two industry standards: </SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo2; tab-stops: list .5in"><SPAN style="mso-bidi-font-size: 10.0pt">-<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN><SPAN style="mso-bidi-font-size: 10.0pt">FIPS 140 for cryptographic modules, and </SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo2; tab-stops: list .5in"><SPAN style="mso-bidi-font-size: 10.0pt">-<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN><SPAN style="mso-bidi-font-size: 10.0pt">Common Criteria for Information Technology Security Evaluation.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt"></SPAN>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt">FIPS stands for Federal Information Processing Standard.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The full title of FIPS 140 is �<I><A href="http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf"><FONT color=red>FIPS 140-2: Security Requirement for Cryptographic Modules</FONT></A>.</I>�<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>It is published by the <A href="http://www.nist.gov/"><FONT color=red>U.S. National Institute of Standards and Technology (NIST)</FONT></A><FONT color=red>.</FONT><SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Hardware, firmware or software cryptographic modules are all tested and validated against the standard.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The cryptographic algorithms are NIST approved.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>FIPS 140-3 is currently being drafted and representatives from Oracle will attend the upcoming FIPS 140-3 Software Security Workshop.</SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt"></SPAN>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt"><A href="http://www.commoncriteriaportal.org/"><FONT color=red>Common Criteria</FONT></A> (CC) is also known as ISO standard 15048.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The full title of the standard is �<I>Common Criteria for Information Technology Security Evaluation</I>". <B><SPAN style="mso-spacerun: yes">&nbsp;</SPAN></B>The Common Criteria is a single framework of evaluation criteria for products or systems.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>It is designed to look at the whole development lifecycle: from design, implementation, testing to delivery and installation of the product or system by a third party, in order to provide assurance that development practices have been documented, followed and enforced correctly.</SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt"></SPAN>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt">A common misconception about the Common Criteria is that the entire product is always evaluated in this process.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>In fact, it is the security-related functions and the parts of the product that interact with those security functions that are evaluated.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>These make up the scope of the evaluation, a.k.a. �<I>Target of Evaluation</I>�.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The product is installed in an evaluated configuration, whereby some of the product functionality may be disabled but the product must be able to function normally.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Information on what exactly has been evaluated is found in a document called the �<I>Security Target</I>�.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This document is publicly available once a product has been certified.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Security Targets for Oracle software are available on the <A href="http://www.oracle.com/technology/deploy/security/seceval/oracle-common-criteria-evaluated.html"><FONT color=red>Security Evaluation</FONT></A> page on <A href="http://www.oracle.com/technology/deploy/security/index.html"><FONT color=red>Oracle Technology Network</FONT></A>.</SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt"></SPAN>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt">To date Oracle has completed four FIPS 140 validations and 15 Common Criteria evaluations.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>A listing of the evaluations that have been obtained or are currently underway can be <SPAN style="COLOR: black">found on <A href="http://www.oracle.com/technology/deploy/security/seceval/security-evaluations.html"><SPAN style="COLOR: black"><FONT color=red>Oracle�s Security Evaluation status page</FONT></SPAN></A><FONT color=red>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></FONT></SPAN></SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt"></SPAN>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt">Note that Oracle not only performs evaluations, but it is also actively participating in the development of the Common Criteria.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Oracle is a member of the Common Criteria Vendors Forum (CCVF) that works with the Common Criteria International organisations to enhance the Common Criteria and address common issues within the criteria.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>In a <A href="http://blogs.oracle.com/security/2006/08/28"><FONT color=red>previous blog entry</FONT></A>, Duncan Harris discussed some of the limitations with the current version of the Common Criteria.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt"></SPAN>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-bidi-font-size: 10.0pt">More information on <A href="http://www.oracle.com/security/software-security-assurance.html"><FONT color=red>Oracle Software Security Assurance</FONT></A> is available on Oracle.com.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The <A href="http://www.oracle.com/technology/deploy/security/seceval/index.html"><FONT color=red>Security Evaluation</FONT></A> page on Oracle Technology Network provides detailed information about Oracle's involvement with Security Evaluations.</SPAN></P></p>]]></description>
         <link>http://blogs.oracle.com/security/2008/03/oracle_and_security_evaluation.html</link>
         <guid>http://blogs.oracle.com/security/2008/03/oracle_and_security_evaluation.html</guid>
        
        
         <pubDate>Tue, 11 Mar 2008 08:37:29 -0800</pubDate>
      </item>
            <item>
         <title>SQL Injection Tutorial Now Available!</title>
         <description><![CDATA[<p><P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif size=3>Hello, this is Shirley Ann Stern!<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Recent security research indicates that SQL injection attacks constitute one of the most prevalent types of threats to IT environments.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>For example, in its �</FONT><A href="http://www.sans.org/top20/?portal=d2ed15aa7078773b4da7c928e8565dcc"><FONT face=Geneva,Arial,Sans-Serif color=red size=3>Top 20</FONT></A><FONT face=Geneva,Arial,Sans-Serif><FONT size=3>�, SANS identifies SQL Injection as a major threat to Web applications.<SPAN style="mso-spacerun: yes">&nbsp;&nbsp;</SPAN></FONT></FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif size=3></FONT>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif size=3>SQL injection is one of the most common forms of attacks carried out at the application layer.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>In layman�s terms, SQL Injection attacks are designed to leverage improper coding of web applications that, in the absence of proper input validation, allow a malicious attacker insert string input to an application, and as a result, send potentially harmful SQL commands to the application�s back-end database.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN><SPAN style="mso-bidi-font-size: 9.0pt">Although any program or application (that is powered by a database) may be vulnerable to SQL injections, web applications are at a higher risk because they often allow an attacker to perpetrate SQL injection attacks without being authenticated to the targeted database or application.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></SPAN>The potential consequences of these attacks are serious.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>A successful SQL Injection attack can allow the attacker to gather sensitive data, manipulate database information, and in some instances, to change the structure of the database, deny legitimate access to it, or grant unauthorized privileges to himself or others. </FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif size=3></FONT>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif size=3>An important objective of </FONT><A href="http://www.oracle.com/security/software-security-assurance.html"><FONT face=Geneva,Arial,Sans-Serif color=red size=3>Oracle Software Security Assurance</FONT></A><FONT face=Geneva,Arial,Sans-Serif size=3> is that we provide information to customers that helps enable them to use our products securely.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>To this end, we have developed training materials titled<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>�<I><A href="http://st-curriculum.oracle.com/tutorial/SQLInjection/index.htm"><FONT color=red>Defending Against SQL Injection Attacks</FONT></A>.</I>�<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Available now, this training content is available online and can also be downloaded so that offline studying (while in the train for your morning commute) is possible.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>�<I>Defending Against SQL Injection Attacks�</I> highlights some of the coding practices required to eliminate SQL injection vulnerabilities when developing in an Oracle environment.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Oracle recommends that anyone who develops Internet applications that access an Oracle database review these materials.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Note that this tutorial will also be available through </FONT><A href="http://www.oracle.com/education/index.html"><FONT face=Geneva,Arial,Sans-Serif color=red size=3>Oracle University</FONT></A><FONT face=Geneva,Arial,Sans-Serif size=3> as a lesson in the instructor-led course �<I>Oracle Database 11g: Advanced PL/SQL</I>�, which is scheduled to be available in April 2008. </FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif size=3></FONT>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><FONT face=Geneva,Arial,Sans-Serif>More information on </FONT><A href="http://www.oracle.com/security/software-security-assurance.html"><FONT face=Geneva,Arial,Sans-Serif color=red>Oracle Software Security Assurance</FONT></A><FONT face=Geneva,Arial,Sans-Serif> is available on </FONT><A href="http://www.oracle.com/security/"><FONT face=Geneva,Arial,Sans-Serif color=red>Oracle.com</FONT></A><FONT face=Geneva,Arial,Sans-Serif>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Various trainings, including �<I><A href="http://st-curriculum.oracle.com/tutorial/SQLInjection/index.htm"><FONT color=red>Defending Against SQL Injection Attacks</FONT></A></I>� are available on the </FONT><A href="http://st-curriculum.oracle.com/"><FONT face=Geneva,Arial,Sans-Serif color=red>Server Technologies Curriculum Web Site</FONT></A><FONT face=Geneva,Arial,Sans-Serif>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The </FONT><A href="http://www.oracle.com/technology/deploy/security/index.html"><FONT face=Geneva,Arial,Sans-Serif color=red>Security Technology Center</FONT></A><FONT face=Geneva,Arial,Sans-Serif> and </FONT><A href="http://www.oracle.com/security/resource-library.html"><FONT face=Geneva,Arial,Sans-Serif color=red>Oracle Software Security Assurance Resource Library</FONT></A><FONT face=Geneva,Arial,Sans-Serif> also include a number of useful links to security trainings and white papers.</FONT><SPAN style="mso-spacerun: yes">&nbsp; </SPAN></SPAN></P></p>]]></description>
         <link>http://blogs.oracle.com/security/2008/02/sql_injection_tutorial_now_ava.html</link>
         <guid>http://blogs.oracle.com/security/2008/02/sql_injection_tutorial_now_ava.html</guid>
        
        
         <pubDate>Mon, 18 Feb 2008 07:04:33 -0800</pubDate>
      </item>
            <item>
         <title>To Patch Or Not To Patch?</title>
         <description><![CDATA[<p><P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif>Hello, this is Eric Maurice!</FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif></FONT>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif>A security vendor recently issued a press release that revealed the results of an informal survey it conducted of Database Administrators conducted at Oracle Users Group meetings throughout the United States.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The vendor allegedly found that two-thirds of the 305 respondents had never installed a </FONT><A href="http://www.oracle.com/technology/deploy/security/alerts.htm"><FONT face=Geneva,Arial,Sans-Serif color=red>Critical Patch Update</FONT></A><FONT face=Geneva,Arial,Sans-Serif>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>A number of outlets including blogs and media publications commented on these findings.</FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif></FONT>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif>It is difficult to draw firm conclusions from this survey because of the relatively small size of the sample, absence of information about representativity of the sample, and the formulation of the questions themselves.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>However this survey is interesting to security professionals insofar as it reinforces the importance of patching and brings to light a new element: the psychology of patching.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif></FONT>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif>Commenting in a </FONT><A href="http://www.petefinnigan.com/weblog/archives/00001141.htm"><FONT face=Geneva,Arial,Sans-Serif color=red>blog entry</FONT></A><FONT face=Geneva,Arial,Sans-Serif>, Pete Finnigan made an interesting comment: �<I>I am starting to get the impression from talking to a lot of people that the issue has become psychological, a lot of companies believe it�s difficult, that it will fail and that everything in the organization needs to be regression tested.�</I><SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Security professionals are periodically faced with the decision �to patch or not to patch.�<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>For some, this decision is very difficult because it comes down to weighing the known and immediate consequences of the patching procedure (significant effort for testing and deploying the patches, and the impact of temporarily affecting production environments) versus the unknown and hard-to-predict consequences of keeping known vulnerabilities unpatched (damages resulting from an incident that was enabled by the presence of the unpatched vulnerability).<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>It is generally in human nature to find known and immediate difficulties more daunting than those that are uncertain and more remote, though the uncertain ones might have much more critical and threatening impact.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Can the decision not to patch be likened to the decision by careless drivers to run yellow or red lights to avoid being delayed for three or four minutes, while consciously ignoring the potential price of such action (possible death or injury) if collisions were to occur?<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif></FONT>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif>The only solutions for removing the psychological objections to patching are mandating the application of security patches as a part of the normal maintenance of production systems <I>or</I> providing objective measures to determine whether patching is required on certain systems at a certain point in time.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif></FONT>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif>Patching decisions can only become objective business decisions if they are made after computing the expected cost or benefit resulting from the application of the security patches on a given system.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The costs of the patching effort and its impact on production environments need to be measured against the probability that the unplugged vulnerability will result in a successful exploit, multiplied by the financial liability that this successful exploitation would create for the organization.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Unfortunately, there is no such thing as an actuarial table that would provide accurate statistical measures of the chance of occurrence of a specific incident or exploit; and furthermore, measuring the full financial impact (direct and indirect costs) of a potential incident is extremely difficult, therefore a lot of guesswork has to take place.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This is why most security-conscious organizations require mandatory patching, instead of attempting to develop a comprehensive quantitative risk model for all their systems in their environment.</FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif></FONT>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif>Oracle recommends that customers apply the Critical Patch Updates when they become available to maintain a proper security posture.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>However, immediate and systematic application of every security patch on an ongoing basis for all production systems may be difficult or impossible for some organizations because of the complexity of their environment or due to their production requirements.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This is why Oracle has intentionally designed the Oracle Database Server, Oracle Application Server, Oracle Enterprise Manager, and Oracle E-Business Suite R12 patches to be </FONT><A href="http://www.oracle.com/technology/deploy/security/securityfixlifecycle.html"><FONT face=Geneva,Arial,Sans-Serif color=red>cumulative</FONT></A><FONT face=Geneva,Arial,Sans-Serif>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>As a result, each Critical Patch Update for these products contains the security fixes from ALL previous Critical Patch Updates.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The benefit for customers is clear: applying the most recent Critical Patch Update will install all the fixes that were previously released for these products.</FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif></FONT>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif>Note that customers, who are applying the most recent patch sets also get the benefit of previously released security fixes.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>That is because security fixes are also included in patch sets&nbsp;and in new product releases (</FONT><A href="http://www.oracle.com/technology/deploy/security/alerts.htm#Policies"><FONT face=Geneva,Arial,Sans-Serif>Oracle�s policy</FONT></A><FONT face=Geneva,Arial,Sans-Serif> is to first fix security vulnerabilities in the current code, i.e., the code used for the next release of the product).<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The inclusion of security fixes in patch sets and product releases provides customers more patching flexibility, effectively allowing those who are planning to deploy the most recent patch set to �skip� the application of a Critical Patch Update.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif></FONT>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"><FONT face=Geneva,Arial,Sans-Serif>When looking at the previously discussed survey, one is left to wonder if the inclusion of security fixes in patch sets had the undesirable consequence of causing some Oracle DBAs to mostly ignore Critical Patch Updates, opting instead to focus resources on applying patch sets.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>However, <I>Oracle recommends that the Critical Patch Updates remain the primary means of applying security fixes</I> because Critical Patch Updates are released more frequently than patch sets and new product releases.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></FONT></P><br />
<P><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><FONT face=Geneva,Arial,Sans-Serif>You can find more information about Oracle�s security lifecycle policies on the </FONT><A href="http://www.oracle.com/technology/deploy/security/securityfixlifecycle.html"><FONT face=Geneva,Arial,Sans-Serif color=red>Security Vulnerability Fixing Policy and Process</FONT></A><FONT face=Geneva,Arial,Sans-Serif> page on </FONT><A href="http://www.oracle.com/technology/deploy/security/index.html"><FONT face=Geneva,Arial,Sans-Serif>Oracle Technology Network</FONT></A><FONT face=Geneva,Arial,Sans-Serif>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The </FONT><A href="http://www.oracle.com/technology/deploy/security/alerts.htm"><FONT face=Geneva,Arial,Sans-Serif color=red>Critical Patch Updates and Security Alerts page</FONT></A><FONT face=Geneva,Arial,Sans-Serif> also on </FONT><A href="http://www.oracle.com/technology/deploy/security/index.html"><FONT face=Geneva,Arial,Sans-Serif>Oracle Technology Network</FONT></A><FONT face=Geneva,Arial,Sans-Serif> provides detailed information about previously released Critical Patch Updates and Security Alerts.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Additionally, <FONT color=#ff0000><A href="http://www.oracle.com/security/resource-library.html">the Resource Library</A> </FONT>on the </FONT><A href="http://www.oracle.com/security/software-security-assurance.html"><FONT face=Geneva,Arial,Sans-Serif color=red>Oracle Software Security Assurance web site</FONT></A><FONT face=Geneva,Arial,Sans-Serif> provides a number of links to useful security resources, including a </FONT><A href="http://www.oracle.com/technology/deploy/security/pdf/cpu_whitepaper.pdf"><FONT face=Geneva,Arial,Sans-Serif>white paper discussing how to develop a repeatable Critical Patch Update process</FONT></A></SPAN></P></p>]]></description>
         <link>http://blogs.oracle.com/security/2008/01/to_patch_or_not_to_patch.html</link>
         <guid>http://blogs.oracle.com/security/2008/01/to_patch_or_not_to_patch.html</guid>
        
        
         <pubDate>Thu, 31 Jan 2008 11:43:22 -0800</pubDate>
      </item>
            <item>
         <title>January 2008 Critical Patch Update Released</title>
         <description><![CDATA[<p><P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif><FONT size=3>Hello, this is Eric Maurice again!<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></FONT></FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif size=3></FONT>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif size=3>Oracle today released the January 2008 Critical Patch Update (</FONT><A href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2008.html"><B><FONT face=Geneva,Arial,Sans-Serif color=red size=3>CPUJan2008</FONT></B></A><FONT face=Geneva,Arial,Sans-Serif><FONT size=3>).<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This Critical Patch Update (CPU) addresses a total of 26 vulnerabilities affecting Oracle Database Server, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite, and Oracle PeopleSoft Enterprise.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Eight of these vulnerabilities are specific to Oracle Database Server, including one vulnerability affecting Oracle Database Server 11g on Linux.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></FONT></FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif size=3></FONT>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif size=3>While none of the Oracle Database Server fixes requires patching the database client-only installations, this Critical Patch Update includes fixes for six Oracle Application Server vulnerabilities, and two of these fixes are for client installations.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The two Application Server client fixes address severe vulnerabilities affecting </FONT><A href="http://www.oracle.com/technology/software/products/developer/htdocs/jinit.htm"><B><FONT face=Geneva,Arial,Sans-Serif color=red size=3>JInitiator</FONT></B></A><FONT face=Geneva,Arial,Sans-Serif><FONT size=3>, a web browser extension that enables end users to run Oracle Forms Services applications within their browser.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>These two vulnerabilities have received a CVSS score of 9.3 because they could allow an attacker to gain full control of the targeted <I>client</I> (e.g. a laptop or workstation) at the Operating System level.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Note however that these two vulnerabilities cannot be used to exploit a server.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></FONT></FONT></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Geneva,Arial,Sans-Serif size=3></FONT>&nbsp;</P><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><FONT face=Geneva,Arial,Sans-Serif>The </FONT><A href="http://www.oracle.com/technology/deploy/security/alerts.htm"><STRONG><FONT face=Geneva,Arial,Sans-Serif color=red>Critical Patch Updates and Security Alerts page</FONT></STRONG></A><FONT face=Geneva,Arial,Sans-Serif> on </FONT><A href="http://www.oracle.com/technology/index.html"><STRONG><FONT face=Geneva,Arial,Sans-Serif color=#ff0000>Oracle Technology Network</FONT></STRONG></A><FONT face=Geneva,Arial,Sans-Serif> provides detailed information about this CPU, as well as previous CPUs and Security Alerts.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Oracle <STRONG><SPAN style="COLOR: red"><A href="http://metalink.oracle.com/metalink/plsql/showdoc?db=Not&amp;id=394487.1"><FONT color=#ff0000>MetaLink Note&nbsp;394487.1</FONT></A></SPAN></STRONG> (subscription to MetaLink required) explains Oracle's implementation of the CVSS standard.&nbsp; The </FONT><A href="http://www.oracle.com/security/resource-library.html"><STRONG><FONT face=Geneva,Arial,Sans-Serif color=red>Resource Library</FONT></STRONG></A><FONT face=Geneva,Arial,Sans-Serif> on the </FONT><A href="http://www.oracle.com/security/software-security-assurance.html"><STRONG><FONT face=Geneva,Arial,Sans-Serif color=red>Oracle Software Security Assurance web site</FONT></STRONG></A><FONT face=Geneva,Arial,Sans-Serif> also provides a number of links to useful security resources.</FONT></SPAN></p>]]></description>
         <link>http://blogs.oracle.com/security/2008/01/january_2008_critical_patch_up.html</link>
         <guid>http://blogs.oracle.com/security/2008/01/january_2008_critical_patch_up.html</guid>
        
        
         <pubDate>Tue, 15 Jan 2008 16:02:48 -0800</pubDate>
      </item>
            <item>
         <title>Getting Started With A Secure Configuration Effort</title>
         <description><![CDATA[<p><P class=MsoNormal style="MARGIN: 0in 0in 0pt">Hi, this is Chad Hughes again.&nbsp; In order to maintain a proper security posture, an organization must commit to developing and maintaining secure configurations on all layers of its environment.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Such commitment may require the organization to reconsider commonly accepted assumptions, dispel security myths, or just �get back to the basics� of security.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">For example, the �<A href="http://www.privacyrights.org/ar/ChronDataBreaches.htm">Chronology of Data Breaches</A>� compiled by the Privacy Rights Clearinghouse includes a number of instances where the improper disclosure of sensitive information could have been prevented by common sense, or basic security policies and procedures.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>It is therefore not surprising that a <A href="http://www.oracle.com/security/security-worries.pdf">recent Ponemon Institute survey sponsored by Oracle</A> found that �42 % of IT practitioners believe their organizations can do more to prevent loss or theft of confidential information� and �Only 55 % of IT respondents believe they would be able to notify users and customers impacted by a data breach.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Of course, these issues are not limited to businesses, but also impact government organizations as well.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>For example, a <A href="http://www2.csoonline.com/blog_view.html?CID=32867">recent article on CSO Online</A> related how the U.S. Department of Agriculture managed to expose thousands of social security numbers.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">Incorrect technical assumptions can also be very damaging.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>For example, while many IT professionals may think that databases are usually sheltered within corporate firewalls, in&nbsp;his 2005 and most recent 2007 �Database Exposure Survey � research, David Litchfield found that many databases are directly exposed to the Internet.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Unfortunately, generally innocuous search sites such as Google can be used to search for specific systems and services exposed to the Internet, and known vulnerabilities on those systems.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>See for example <A href="http://www.securityfocus.com/news/11417">�Google Code Search peers into programs' flaws� on SecurityFocus</A> or <A href="http://www.securitydevcenter.com/pub/a/security/2004/10/07/googling_for_vulnerabilities.html">�Google Your Site For Security Vulnerabilities� on Security Devcenter</A>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Michael Sutton's blog entry, �<A href="http://portal.spidynamics.com/blogs/msutton/archive/2006/09/26/How-Prevalent-Are-SQL-Injection-Vulnerabilities_3F00_.aspx">How Prevalent Are SQL Injection Vulnerabilities</A><A href="http://portal.spidynamics.com/blogs/msutton/archive/2006/09/26/How-Prevalent-Are-SQL-Injection-Vulnerabilities_3F00_.aspx"></A><A href="http://portal.spidynamics.com/blogs/msutton/archive/2006/09/26/How-Prevalent-Are-SQL-Injection-Vulnerabilities_3F00_.aspx">,�</A> includes an example of a simple Google query intended to find databases exposed directly or indirectly to the Internet.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">A myopic concern with external threats and hackers may also lead organizations on the wrong path by focusing the security effort exclusively towards securing the perimeter of the organization.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>For example, a quick glance at the web site of <A href="http://www.cybercrime.gov/ccnews.html">the Computer Crime &amp; Intellectual Property Section of the United States Department of Justice</A> shows that employees (both current and former) and contractors represent a significant portion of perpetrators.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>When hardening exercises are performed in production environments, far too often only the Internet-facing edge of production environments get the hardening treatment, creating a hard, crunchy shell, but leaving a soft, gooey center.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The problem is that the hard crunchy shell often allows outside access to sensitive resources at the center to provide legitimate access to a set of services or applications.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>When hardening the center is neglected, leaving it soft and gooey, it may be vulnerable to attack through these holes intentionally left open in the hard, crunchy shell.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>As a result, it is not uncommon to witness situations where a compromised web applications server has resulted in the compromise of internal servers, sometimes even granting the attacker with privileged access on these machines.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>An unprotected center also may unnecessarily expose valuable resources to internal threats such as human error, disgruntled employees, and malware propagation.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">Even when an organization understands the need to work on all layers of its production environment, often enough, the secure configuration effort is hampered by the belief that such effort will require a tremendous amount of resources.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>However, this is not necessarily true!</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">The effort of limiting the attack surface of the environment can yield significant security benefits.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This is because, in complex applications, no one-size-fits-all configuration can possibly accommodate the needs of every customer.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>In most instances, customizing the installation to leave the proper balance of functionality is desirable to meet production and security objectives.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Production systems that are left in their default state are likely to contain unused functionality that varies from customer to customer.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Unused functionality in production environments needlessly increases the exposure surface, or total number of possible attack vectors.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>To reduce the exposure risk, customers can limit production system functionality to that which is required.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">The greatest advantage of reducing surface area of production environments is that it contributes to significantly increasing the security posture of the organization at a relatively small cost. This is particularly true when hardening can be automated so the incremental cost to harden is low. Hardening production environments by reducing the attack surface is relatively inexpensive compared to many other defense in depth safeguards: it typically doesn�t require expenses for acquiring additional licenses or hardware; hardening effort can be incremental so as to not dramatically impact production environment, etc.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Most importantly, the security return of a surface reduction effort is obvious -- if a defect is found in functionality you're not using, you're likely to be protected.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>And you're likely to be protected before patching, before upgrading, before employing a work-around...nothing additional is required.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>If a 0-day exploit happens to reside in unused functionality that was already disabled by a previous hardening exercise, you're protected.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">For more information on Oracle�s Secure Configuration initiative, see my previous blog entry �<A href="http://blogs.oracle.com/security/2006/12/08/">Oracle�s Approach to Configuration Hardening</A>.�<SPAN style="mso-spacerun: yes">&nbsp;&nbsp;</SPAN><SPAN style="mso-spacerun: yes">&nbsp;&nbsp;</SPAN>Finally, the <A href="http://www.oracle.com/security/resource-library.html">Oracle Software Security Assurance Resource Library</A> includes valuable links to technical white papers and security checklists providing guidelines for reducing surface areas, or engaging in a more comprehensive hardening effort.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">NOTE: <SPAN class=body1><SPAN style="LETTER-SPACING: 0pt; mso-bidi-font-family: 'Times New Roman'; mso-ansi-font-size: 12.0pt; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">Opinions expressed by the authors of the white papers and articles cited in this blog entry do not reflect the position of Oracle. Any advice, conclusion, or recommendations discussed on these sites (or sites they link to) are not validated by Oracle.</SPAN></SPAN></P></p>]]></description>
         <link>http://blogs.oracle.com/security/2007/12/getting_started_with_a_secure.html</link>
         <guid>http://blogs.oracle.com/security/2007/12/getting_started_with_a_secure.html</guid>
        
        
         <pubDate>Fri, 07 Dec 2007 17:39:32 -0800</pubDate>
      </item>
            <item>
         <title>Understanding the Common Vulnerability Scoring System (CVSS): Part 2</title>
         <description><![CDATA[<p><P class=MsoNormal style="MARGIN: 0in 0in 0pt">Hi, this is Eric Maurice again! Last week, we discussed the objectives of CVSS and how it impacted the scoring philosophy of the standard.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Today, we are going to take a closer look at the formula vendors use to compute CVSS Base Scores.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">The CVSS Base Score is computed from six criteria, known collectively as the �<I>Base Metrics</I>�, representing �<I>the most fundamental, immutable qualities of a vulnerability</I>�.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>These criteria are:</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l7 level1 lfo24; tab-stops: list .25in">1.<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN><I>Access Vector</I>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This measures �<I>how remote an attacker can be to attack a target</I>�.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The possible Access Vector values are <I>Local, Adjacent Network, </I>and<I> Network;</I></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l7 level1 lfo24; tab-stops: list .25in">2.<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN><I>Access Complexity</I>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This measures �<I>the complexity of attack required to exploit the vulnerability once an attacker has gained access to the target system</I>�.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The possible Access Complexity values are <I>High, Medium </I>and <I>Low;</I></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l7 level1 lfo24; tab-stops: list .25in">3.<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN><I>Authentication</I>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This measures �<I>the number of times an attacker must authenticate to the target system in order to exploit the vulnerability</I>�.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The possible Authentication values are <I>Multiple, Single, </I>and <I>None;</I></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l7 level1 lfo24; tab-stops: list .25in">4.<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN><I>Confidentiality Impact</I>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This measures �<I>the impact on confidentiality of a successful exploit of the vulnerability on the target system</I>�, that is to say, improper information disclosure.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The possible Confidentiality Impact values are <I>None, Partial, </I>and <I>Complete;</I></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l7 level1 lfo24; tab-stops: list .25in">5.<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN><I>Integrity Impact</I>. This measures �<I>the impact on integrity of a successful exploit of the vulnerability on the target system</I>�, that is to say, data corruption.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The possible Integrity Impact values are <I>None, Partial, </I>and <I>Complete;</I></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l7 level1 lfo24; tab-stops: list .25in">6.<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN><I>Availability Impact</I>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This measures �<I>the impact on availability of a successful exploit of the vulnerability on the target system</I>�, that is to say, denial of service.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The possible Availability Impact values are <I>None, Partial, </I>and <I>Complete.</I></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l7 level1 lfo24; tab-stops: list .25in"><EM></EM>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">A numerical value is assigned to each of the three possible answers for each of the six criteria.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Then a formula, known as the �<A href="http://www.first.org/cvss/cvss-guide.html#i3.2.1">Base Equation</A>�, is used to assign weight to each of the criteria, combine the weighted values, and derive the Base Score.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The application of the Base Equation formula yields in a maximum score of 7.5 for vulnerabilities typically found in Oracle products (it would be extraordinary if an Oracle security bug would result in a <U>complete</U> compromise of the underlying operating system).<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Note that the <A href="http://nvd.nist.gov/">National Vulnerability Database</A> considers CVSS scores between 7.0 and 10.0 to be �high�.<SPAN style="mso-spacerun: yes">&nbsp;</SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">The <A href="http://www.nist.gov/">National Institute of Standards and Technology</A> (NIST) hosts a <A href="http://nvd.nist.gov/cvss.cfm?calculator&amp;version=2">CVSS 2.0</A> calculator online.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This neat utility provides the ability to compute the score without necessarily manually dealing with the Base, Temporal, or Environmental equations.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Let�s take one of the vulnerabilities addressed in the October 2007 CPU <FONT color=black>(</FONT><A href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2007.html"><FONT color=red>CPUOct2007</FONT></A>); the vulnerability DB01 had the following particularities:</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l24 level1 lfo23; tab-stops: list .5in">-<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN>Exploitability Metrics:</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l24 level2 lfo23; tab-stops: list 1.0in"><SPAN style="FONT-FAMILY: 'Courier New'; mso-bidi-font-family: 'Times New Roman'">o<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN>Related exploit range (AccessVector): Network</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l24 level2 lfo23; tab-stops: list 1.0in"><SPAN style="FONT-FAMILY: 'Courier New'; mso-bidi-font-family: 'Times New Roman'">o<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN>Attack complexity (AccessComplexity): Low</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l24 level2 lfo23; tab-stops: list 1.0in"><SPAN style="FONT-FAMILY: 'Courier New'; mso-bidi-font-family: 'Times New Roman'">o<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN>Level of authentication needed (Authentication): Single Instance</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.75in; TEXT-INDENT: -0.25in; mso-list: l6 level1 lfo25; tab-stops: list .75in">-<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN>Impact Metrics:</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo20; tab-stops: list 1.0in"><SPAN style="FONT-FAMILY: 'Courier New'; mso-bidi-font-family: 'Times New Roman'">o<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN>Confidentiality impact (ConfImpact): Partial</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo20; tab-stops: list 1.0in"><SPAN style="FONT-FAMILY: 'Courier New'; mso-bidi-font-family: 'Times New Roman'">o<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN>Integrity impact (IntegImpact): Partial</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo20; tab-stops: list 1.0in"><SPAN style="FONT-FAMILY: 'Courier New'; mso-bidi-font-family: 'Times New Roman'">o<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN>Availability impact (AvailImpact): Partial</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">When entering these values, the calculator provides the score of 6.5 as reported in the CPU documentation.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">Oracle quickly realized some limitations of the CVSS base scoring system.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>One is that CVSS does not distinguish between, for example, the disclosure of only a <I>single</I> database record and the disclosure of <I>all</I> data in a database.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Oracle therefore introduced the �Partial+� rating to denote such rare situations where the impact of the vulnerability can result in widespread impacts while partial means only limited impact.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Note that Oracle uses the Partial numeric value assigned by CVSS for both Partial and Partial+, so that Oracle does not deviate from the standard.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">For more information, see:</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l17 level1 lfo7; tab-stops: list .25in">-<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN><A href="http://metalink.oracle.com/metalink/plsql/showdoc?db=Not&amp;id=394487.1">Oracle MetaLink Note 394487.1</A> (subscription to MetaLink required) explains Oracle's implementation of the CVSS standard.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l17 level1 lfo7; tab-stops: list .25in">-<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN><A href="http://metalink.oracle.com/metalink/plsql/showdoc?db=Not&amp;id=394486.1"><FONT color=red>Oracle MetaLink Note 394486.1</FONT></A> (subscription to MetaLink required) provides a detailed explanation of Oracle�s risk matrices.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l17 level1 lfo7; tab-stops: list .25in">-<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN>The <A href="http://www.oracle.com/technology/deploy/security/alerts.htm"><FONT color=red>Critical Patch Updates and Security Alerts page</FONT></A> on <A href="http://www.oracle.com/technology/index.html">Oracle Technology Network</A> provides detailed information about previously released CPUs and Security Alerts.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l17 level1 lfo7; tab-stops: list .25in">-<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN>The <A href="http://www.first.org/cvss/cvss-guide.html"><FONT color=red>Guide to the Common Vulnerability Scoring System version 2.0</FONT></A> is available online, and it includes the scoring formulas set forth by the standard.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P></p>]]></description>
         <link>http://blogs.oracle.com/security/2007/11/understanding_the_common_vulne.html</link>
         <guid>http://blogs.oracle.com/security/2007/11/understanding_the_common_vulne.html</guid>
        
        
         <pubDate>Wed, 07 Nov 2007 08:34:44 -0800</pubDate>
      </item>
            <item>
         <title>Understanding the Common Vulnerability Scoring System (CVSS): Part 1</title>
         <description><![CDATA[<p><P class=MsoNormal style="MARGIN: 0in 0in 0pt">Hi, this is Eric Maurice again! </P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">Following the release of the October CPU (<A href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2007.html"><FONT color=red>CPUOCT2007</FONT></A>), it became clear that there was still a certain level of confusion and misunderstanding about CVSS and how it was implemented by Oracle.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Given this situation, I thought it might be helpful to further talk about CVSS, and specifically, the vulnerability scoring metholodgy implemented in the standard.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-spacerun: yes"></SPAN>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-spacerun: yes"></SPAN>The <A href="http://www.first.org/cvss/"><FONT color=red>Common Vulnerability Scoring System</FONT></A> (CVSS), initially announced in February 2005 on the <A href="http://www.dhs.gov/index.shtm"><FONT color=red>U.S. Department of Homeland Security�s web site</FONT></A>, is designed to �<I>provide open and universally standard severity ratings of software vulnerabilities</I>�.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Oracle was one of the first software vendors to adopt CVSS to provide a standard-based indication of the severity of the vulnerabilities fixed in its products.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Oracle has provided CVSS Base Scores in the risk matrices of the CPU documentation since the October 2006 Critical Patch Update (<A href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2006.html"><FONT color=red>CPUOct2006</FONT></A>).<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>In June 2007, <A href="http://www.first.org/">FIRST</A> (Forum of Incident Response and Security Teams) published the second version of the standards: <A href="http://www.first.org/cvss/cvss-guide.html"><FONT color=red>CVSS 2.0</FONT></A>, which was implemented by Oracle with the October 2007 Critical Patch Update (<A href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2007.html"><FONT color=red>CPUOct2007</FONT></A>).<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Note that in this discussion, we will address the new CVSS 2.0 Scoring System if not otherwise noted</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">Since Oracle implemented CVSS, we periodically receive questions about how the <I>CVSS base metrics scores</I> are calculated.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Specifically, some people find it surprising that vulnerabilities deemed to be particularly critical receive a CVSS base score between 6.5 and 7.5 out of an absolute scale of 10.0.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Understanding the CVSS scoring system requires going back to the objectives of CVSS, and understanding the formulas behind the scores themselves.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>In the first part of this blog series, we will be discussing the objectives of CVSS and how it affected the scoring of vulnerabilities</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">The CVSS web site states that the objective of CVSS is to provide a <I>severity rating for all software vulnerabilities</I>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-spacerun: yes"></SPAN>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-spacerun: yes"></SPAN>This means that CVSS is designed to provide a numeric value (the score) indicative of the relative criticality of a given vulnerability regardless of the type of software it affects, <I>whether it is an Operating System, antivirus, database, mail server, desktop or business application, etc</I>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>As a result of this wide scope of applicability, the standard is <I>intentionally</I> designed to require a complete compromise at the Operating System layer for a given vulnerability to be given a base score of 10.0.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>In other words, a vulnerability with a CVSS Base Score of 10.0 typically signifies a complete compromise of the system, that typically results in allowing the attacker full control, including administrative or �root� privileges at the OS layer.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>An example of the impact of such a vulnerability in a third party product is reported on the National Vulnerability Database as �<EM>The attacker could then install programs; view, change, or delete data; or create new accounts with full user rights</EM><I>.</I>�<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-spacerun: yes"></SPAN>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-spacerun: yes"></SPAN>Due to the nature of the Oracle bugs, vulnerabilities that could result in a complete compromise of the underlying server are rather rare.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>In fact, since the CVSS scoring was implemented by Oracle, the highest-ever CVSS Base Score assigned by Oracle to a vulnerability addressed in the CPU would have been 7.5 if it had been scored under the CVSS 1.0 scoring system.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Note however that CVSS deals with single vulnerabilities, and does not completely account for �blended threats�, that is the combination of attack methods/vectors that could ultimately result in such a very extensive compromise.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>It is therefore very important for organizations to patch all vulnerabilities as soon as possible, as leveraging various vulnerabilities across IT layers may result in a more complete compromise of the targeted system.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">The CVSS system includes three types of score � <I>Base</I>, <I>Temporal</I> and <I>Environmental</I>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Each is designed to measure different attributes of the vulnerability.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Oracle provides the �<I>Base Score</I>� in the CPU documentation.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>It is characterized by the following aspects:</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l9 level1 lfo19; tab-stops: list .25in">-<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN>The Base Score is <I>specific</I> to a given vulnerability.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l9 level1 lfo19; tab-stops: list .25in">-<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN>It <I>does not change over time</I>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This is where the �Temporal Metrics� come into play to measure, for example, additional exposure resulting from the availability of exploit code.<SPAN style="mso-spacerun: yes">&nbsp;</SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l9 level1 lfo19; tab-stops: list .25in">-<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN>It is <I>not specific to a customer�s technical IT environment</I>.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This is where the �Environmental Metrics� come into play, to measure, for example, the likelihood of collateral damages to other systems and applications.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">The CVSS documentation states that computing the Temporal and Environmental Metrics scores is optional.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>While computing all three scores can provide a granular risk rating (specific to a <I>given</I> <I>vulnerability</I> in a <I>specific environment</I> at <I>one point in time</I>), most customers find this process to be too cumbersome, and they rely exclusively on the Base Score to assess the criticality of vulnerabilities and the priority given to patching them.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN></P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="mso-spacerun: yes"></SPAN>&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">Next week, we will be looking into more details on how the Base Score is computed using the �Base Equation� of CVSS.</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">For more information, see:</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l16 level1 lfo7; tab-stops: list .25in">-<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN><A href="http://metalink.oracle.com/metalink/plsql/showdoc?db=Not&amp;id=394487.1">Oracle MetaLink Note 394487.1</A> (subscription to MetaLink required) explains Oracle's implementation of the CVSS standard</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l16 level1 lfo7; tab-stops: list .25in">-<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN><A href="http://metalink.oracle.com/metalink/plsql/showdoc?db=Not&amp;id=394486.1"><FONT color=red>Oracle MetaLink Note 394486.1</FONT></A> (subscription to MetaLink required) provides a detailed explanation of Oracle�s risk matrices</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l16 level1 lfo7; tab-stops: list .25in">-<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN>The <A href="http://www.oracle.com/technology/deploy/security/alerts.htm"><FONT color=red>Critical Patch Updates and Security Alerts page</FONT></A> on <A href="http://www.oracle.com/technology/index.html">Oracle Technology Network</A> provides detailed information about previously released CPUs and Security Alerts</P><br />
<P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l16 level1 lfo7; tab-stops: list .25in">-<SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN>The <A href="http://www.first.org/cvss/cvss-guide.html"><FONT color=red>Guide to the Common Vulnerability Scoring System version 2.0</FONT></A><FONT color=red> </FONT><FONT color=black>is</FONT> available online, and it includes the scoring formulas set forth by the standard.</P><br />
<P>&nbsp;</P></p>]]></description>
         <link>http://blogs.oracle.com/security/2007/11/understanding_the_common_vulne_1.html</link>
         <guid>http://blogs.oracle.com/security/2007/11/understanding_the_common_vulne_1.html</guid>
        
        
         <pubDate>Fri, 02 Nov 2007 07:48:15 -0800</pubDate>
      </item>
      
   </channel>
</rss>
