Pete Finnigan's Oracle Security Forum (http://www.petefinnigan.com/forum/yabb/YaBB.cgi)
Oracle Security >> Oracle Security >> Oracle client patching (Cpu July 2006) and SOx
(Message started by: Pete Finnigan on Jul 23rd, 2006, 11:55pm)

Title: Oracle client patching (Cpu July 2006) and SOx
Post by Pete Finnigan on Jul 23rd, 2006, 11:55pm
Hi,

Metalink Note:372927.1, about the latest CPU of Oracle (released 18th July), has an interesting paragraph regarding client patching.

"..The fourth vulnerability which allows an untrusted, malicious server to cause the client to terminate and additionally may allow the execution of arbitrary code on the client."  

Does SOx require that oracle client-only machines that connect to SOx material databases are patched because of this type of vulnerability? We apply windows patches  to clients for the same reason..

Who can share SOx audit experiences with regards to client-only installations?

Regards,
Andre



Powered by YaBB 1 Gold - SP 1.4!
Forum software copyright © 2000-2004 Yet another Bulletin Board