Channel News and Analysis - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Cisco Small Business Advantage
  • Register for WES 2010 by February 19 and save $400.
  • up.time Easily Monitors Virtual/Physical/Cloud. Free Trial.
  • Seagate® Barracuda® drives fit every desktop need.
  • MSP Partners helps solution providers stay competitive.
  • Learn more about EnterpriseDB @ the Postgres Center
  • Earn 40-50% margins. Zenith open houses show how.
  • CDW Healthcare offers the IT solutions you need.
  • One number. One voicemail. Sprint Mobile Integration.
  • FREE Sophos Encryption Tool: Encrypt, compress and share files easily.
  • Give your customers more with LSI 6Gb/s solutions.






  • Channel Insider conferred 75 awards to vendor, distribution, solution provider and industry groups for performance excellence. Check out all the winners in the 28 Bull’s Eye Award categories.
    >> Bull’s Eye Central


     

    Major Oracle Patch Covers Enterprise Products, Database Server

    in Channel News and Analysis


    Article Rating:starstarstarstarstar / 0
    Article Views: 2076

    Rate This Article:
    Add This Article To:
    The third cumulative patch from Oracle since the start of its new system applies a set of 49 fixes to a wide array of offerings.

    Oracle has released a set of 49 patches that addresses new flaws in multiple versions of its Database Server, Application Server, Collaboration Suite, E-Business and Applications, and Enterprise Manager products.

    The patches are available on OTN (the Oracle Technology Network).

    The product flaws vary in terms of exploitability. Oracle Database has 12 flaws, including a flaw in Database 10g's Oracle OLAP (online analytical processing) that requires Database privilege—execute on olapsys—but which, according to Oracle's posting, is both easily accessible and would have a wide impact.

    Oracle's Application Server also has a dozen flaws that span the range in terms of authorization required, severity of impact and ease of exploitation. Collaboration Suite has six flaws and E-Business Suite has 17, while Enterprise Manager has two.

    Resource Library:
    The new database vulnerabilities addressed by this Critical Patch Update don't affect Oracle Database Client-only installations (installations that don't have the Oracle Database Server installed).

    Therefore, according to Oracle's posting, it is not necessary to apply this Critical Patch Update to client-only installations if a prior Critical Patch Update, or Alert 68, has already been applied to the client-only installations.

    Oracle issues a fix for a previous patch that has been determined to be faulty. Click here to read more.

    The Oracle Database Server, Enterprise Manager and Oracle Application Server patches are cumulative, containing all fixes from the previous Critical Patch Update.

    Not so for E-Business Suite or Collaboration Suite patches, however, so customers using these products should refer to previous Critical Patch Updates to identify previous fixes they need to apply.

    This is the third of Oracle's Critical Patch Updates since the company started cumulative patch releases in January.

    Jon Oltsik, an analyst at Enterprise Strategy Group, said that Oracle customers are mostly comfortable with Oracle's new patching strategy, but they would like Oracle to be more proactive with emergency patches.

    "If any are high impact, if I were a customer and had a major investment in Oracle, I wouldn't want to wait around for the cumulative patch release," he said. "I want to know about them immediately and apply them immediately."

    Read more here about Oracle's move to a quarterly patch cycle.

    In contrast, Microsoft offers custom services for big enterprise customers. Oracle has resisted that, Oltsik said, since it's more difficult from a process perspective to offer such services. "[But] if I'm a big customer, I don't care about your processes," he said. "If I'm buying from you, give me good service."

    "People tend to criticize Microsoft from [the standpoint of] general security and number of vulnerabilities," Oltsik said. "But from [the perspective of] patching and management strategies, they're very, very good and flexible. I'd say, more so than Oracle."

    Check out eWEEK.com's for the latest database news, reviews and analysis.





    Discuss Major Oracle Patch Covers Enterprise Products, Database Server
     
    >>> Be the FIRST to comment on this article!
     

     
     
    >>> More Channel News and Analysis Articles          >>> More By Lisa Vaas
     


     


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.

     


    CHANNEL RESOURCE CENTER
     
     
    How much time do you spend hunting for enterprise IT content?
    Let Enterprise TechBrief do the work for you. Aggregated content, tech news, product reviews, vendor updates, how-to’s—all you need to boost your efficiencies and cut costs, all from one place.
    enterprisetechbrief.com
     
    Should You Be Using “up.time”?
    Easily Monitor Virtual, Physical, and Cloud based assets, applications and services from a unified Dashboard with up.time. Deep Monitoring across platforms and along with best-of-breed reporting. Over 700 enterprise customers in 32 countries.
    Free Trial Download Here (Virtual Appliance available)
    Managed service providers are using regulatory compliance and industry standards to win business and give customers peace of mind. Join host Larry Walsh of Ziff Davis Enterprise and his guests on Friday, February 19, 2010, at 1:00 pm ET for a discussion of “Compliance as a Service.”
    Register Today