Feeds

Oracle to provide clearer vulnerability ratings

In at number one it's the latest Buffer Overflow...

Remote control for virtualized desktops

Oracle is to start ranking the severity of security bugs it fixes using an industry-standard scoring system starting with its next quarterly patch update, due on 17 October.

The database giant will grade the threat posed by the bugs it fixes using the Common Vulnerability Scoring System (CVSS). It has also promised to give an easy-to-understand execuctive summary of the flaws it has addressed, highlighting bugs that lend themselves to remote exploitation by hackers. In the past, Oracle published an internally developed risk matrix (example here) along with its quarterly patch cycle but this is to be sidelined if favour of a simpler - and clearer - method of explaining the relative importance of security bugs.

The changes are designed to make it easier for database admins and other users' of Oracle's enterprise software applications to assess the severity of security bugs within their environment and thereby make more informed decisions about how to prioritse security remediation work. That's clearly important because the last two quarterly security updates brought fixes for 65 and 36 flaws respectively, creating plenty of scope for confusion about the relative importance of these various fixes.

"Oracle introduced these changes as the result of feedback we received from many of our customers," Eric Maurice, manager for security in Oracle's Global Technology Business Unit, said in a blog posting. "We hope that these changes will help our customers assess the criticality of the vulnerabilities resolved with each CPU and help them obtain patching decisions from their senior management more quickly."

The changes make sense but fail to address one of the main criticisms of Oracle's security practices - its perceived tardiness in developing security fixes. Oracle has come under fire in the past from security researchers, such as Red Database Security and NGS Software, over the time it takes to release security updates. For example, Red Database Security published information on six flaws in July 2005 after becoming frustrated with a lack of an official security update from Oracle more than 650 days after it notified the software giant about serious flaws. ®

Intelligent flash storage arrays

More from The Register

next story
Be real, Apple: In-app goodie grab games AREN'T FREE – EU
Cupertino stands down after Euro legal threats
Download alert: Nearly ALL top 100 Android, iOS paid apps hacked
Attack of the Clones? Yeah, but much, much scarier – report
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Microsoft: Your Linux Docker containers are now OURS to command
New tool lets admins wrangle Linux apps from Windows
Bada-Bing! Mozilla flips Firefox to YAHOO! for search
Microsoft system will be the default for browser in US until 2020
Facebook, working on Facebook at Work, works on Facebook. At Work
You don't want your cat or drunk pics at the office
Soz, web devs: Google snatches its Wallet off the table
Killing off web service in 3 months... but app-happy bonkers are fine
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Getting ahead of the compliance curve
Learn about new services that make it easy to discover and manage certificates across the enterprise and how to get ahead of the compliance curve.