Feeds

Oracle to provide clearer vulnerability ratings

In at number one it's the latest Buffer Overflow...

Security for virtualized datacentres

Oracle is to start ranking the severity of security bugs it fixes using an industry-standard scoring system starting with its next quarterly patch update, due on 17 October.

The database giant will grade the threat posed by the bugs it fixes using the Common Vulnerability Scoring System (CVSS). It has also promised to give an easy-to-understand execuctive summary of the flaws it has addressed, highlighting bugs that lend themselves to remote exploitation by hackers. In the past, Oracle published an internally developed risk matrix (example here) along with its quarterly patch cycle but this is to be sidelined if favour of a simpler - and clearer - method of explaining the relative importance of security bugs.

The changes are designed to make it easier for database admins and other users' of Oracle's enterprise software applications to assess the severity of security bugs within their environment and thereby make more informed decisions about how to prioritse security remediation work. That's clearly important because the last two quarterly security updates brought fixes for 65 and 36 flaws respectively, creating plenty of scope for confusion about the relative importance of these various fixes.

"Oracle introduced these changes as the result of feedback we received from many of our customers," Eric Maurice, manager for security in Oracle's Global Technology Business Unit, said in a blog posting. "We hope that these changes will help our customers assess the criticality of the vulnerabilities resolved with each CPU and help them obtain patching decisions from their senior management more quickly."

The changes make sense but fail to address one of the main criticisms of Oracle's security practices - its perceived tardiness in developing security fixes. Oracle has come under fire in the past from security researchers, such as Red Database Security and NGS Software, over the time it takes to release security updates. For example, Red Database Security published information on six flaws in July 2005 after becoming frustrated with a lack of an official security update from Oracle more than 650 days after it notified the software giant about serious flaws. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
New 'Cosmos' browser surfs the net by TXT alone
No data plan? No WiFi? No worries ... except sluggish download speed
'Windows 9' LEAK: Microsoft's playing catchup with Linux
Multiple desktops and live tiles in restored Start button star in new vids
iOS 8 release: WebGL now runs everywhere. Hurrah for 3D graphics!
HTML 5's pretty neat ... when your browser supports it
Mathematica hits the Web
Wolfram embraces the cloud, promies private cloud cut of its number-cruncher
Google extends app refund window to two hours
You now have 120 minutes to finish that game instead of 15
Intel: Hey, enterprises, drop everything and DO HADOOP
Big Data analytics projected to run on more servers than any other app
Mozilla shutters Labs, tells nobody it's been dead for five months
Staffer's blog reveals all as projects languish on GitHub
SUSE Linux owner Attachmate gobbled by Micro Focus for $2.3bn
Merger will lead to mainframe and COBOL powerhouse
iOS 8 Healthkit gets a bug SO Apple KILLS it. That's real healthcare!
Not fit for purpose on day of launch, says Cupertino
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.