Feeds

Oracle to provide clearer vulnerability ratings

In at number one it's the latest Buffer Overflow...

Website security in corporate America

Oracle is to start ranking the severity of security bugs it fixes using an industry-standard scoring system starting with its next quarterly patch update, due on 17 October.

The database giant will grade the threat posed by the bugs it fixes using the Common Vulnerability Scoring System (CVSS). It has also promised to give an easy-to-understand execuctive summary of the flaws it has addressed, highlighting bugs that lend themselves to remote exploitation by hackers. In the past, Oracle published an internally developed risk matrix (example here) along with its quarterly patch cycle but this is to be sidelined if favour of a simpler - and clearer - method of explaining the relative importance of security bugs.

The changes are designed to make it easier for database admins and other users' of Oracle's enterprise software applications to assess the severity of security bugs within their environment and thereby make more informed decisions about how to prioritse security remediation work. That's clearly important because the last two quarterly security updates brought fixes for 65 and 36 flaws respectively, creating plenty of scope for confusion about the relative importance of these various fixes.

"Oracle introduced these changes as the result of feedback we received from many of our customers," Eric Maurice, manager for security in Oracle's Global Technology Business Unit, said in a blog posting. "We hope that these changes will help our customers assess the criticality of the vulnerabilities resolved with each CPU and help them obtain patching decisions from their senior management more quickly."

The changes make sense but fail to address one of the main criticisms of Oracle's security practices - its perceived tardiness in developing security fixes. Oracle has come under fire in the past from security researchers, such as Red Database Security and NGS Software, over the time it takes to release security updates. For example, Red Database Security published information on six flaws in July 2005 after becoming frustrated with a lack of an official security update from Oracle more than 650 days after it notified the software giant about serious flaws. ®

Protecting against web application threats using SSL

More from The Register

next story
New 'Cosmos' browser surfs the net by TXT alone
No data plan? No WiFi? No worries ... except sluggish download speed
'Windows 9' LEAK: Microsoft's playing catchup with Linux
Multiple desktops and live tiles in restored Start button star in new vids
iOS 8 release: WebGL now runs everywhere. Hurrah for 3D graphics!
HTML 5's pretty neat ... when your browser supports it
Mathematica hits the Web
Wolfram embraces the cloud, promies private cloud cut of its number-cruncher
Google extends app refund window to two hours
You now have 120 minutes to finish that game instead of 15
Mozilla shutters Labs, tells nobody it's been dead for five months
Staffer's blog reveals all as projects languish on GitHub
SUSE Linux owner Attachmate gobbled by Micro Focus for $2.3bn
Merger will lead to mainframe and COBOL powerhouse
iOS 8 Healthkit gets a bug SO Apple KILLS it. That's real healthcare!
Not fit for purpose on day of launch, says Cupertino
Profitless Twitter: We're looking to raise $1.5... yes, billion
We'll spend the dosh on transactions, biz stuff 'n' sh*t
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.