Oracle's refusal to get specific about the vulnerabilities addressed by a recent patch increase the risk to customers, a pair of Gartner analysts alleged Thursday. . . .. Oracle's refusal to get specific about the vulnerabilities addressed by a recent patch increase the risk to customers, a pair of Gartner analysts alleged Thursday. Gartner's Neil MacDonald and Rich Mogull said that Oracle has declined to provide more detailed information about the vulnerabilities that spawned a patch first released in August, then re-released in October. Although keeping mum is Oracle's standard policy, the analysts took the company to task for not spelling out the consequences of not applying the patch, and more important, whether the vulnerabilities affect older, non-supported versions of Oracle's Database Server, Application Server, and Enterprise Manager. The link for this article located at TechWeb News is no longer available. . The ambiguity surrounding vulnerabilities in the latest updates from Oracle amplifies security concerns for users. Explore further for detailed analysis.. Oracle Vulnerabilities, Patch Management, Risk Assessment, Vulnerability Insights. . LinuxSecurity.com Team
Companies should take the proprietary route to provide security for web services-based transactions over the next three years, according to analysts. In a research paper, Security Pattern Standards Face a Long Road to Maturity, analyst Gartner advises firms to rely on vendor-provided technology to provide security for web services-based transactions until 2006. . .. Companies should take the proprietary route to provide security for web services-based transactions over the next three years, according to analysts. In a research paper, Security Pattern Standards Face a Long Road to Maturity, analyst Gartner advises firms to rely on vendor-provided technology to provide security for web services-based transactions until 2006 , even though it may not comply with standards. Although there are no products as such, major vendors sell application development packages, such as Microsoft's Visual Studio .Net, which have the facility to build security into web services. The Gartner report argues that web services security is immature and that complex, multi-party web services will require newer, more versatile security patterns for electronic transactions. By using XML, Simple Object Access Protocol and Web Services Description Language, WS-Security related specifications are designed to be used together to provide a rich, secure web services environment. The link for this article located at vnunet is no longer available. . Businesses must focus on exclusive technologies for safeguarding online transactions, as suggested by market experts.. Proprietary Solutions, Security Patterns, Web Services Security. . LinuxSecurity.com Team
Although there have been no reported cases of cyberterrorism or hacks of corporate or U.S. government sites, companies must remain vigilant in the coming days, say analysts from the research firm Gartner. Soon after last week's horrific terrorist attacks on U.S. . . . . Although there have been no reported cases of cyberterrorism or hacks of corporate or U.S. government sites, companies must remain vigilant in the coming days, say analysts from the research firm Gartner. Soon after last week's horrific terrorist attacks on U.S. targets, government officials and analysts alike issued warnings that cyberterrorism is likely. Those alerts continue to stand--and won't likely go away soon--based on comments from Gartner analysts during a conference call Monday. The government has carried out "war games" to simulate cyberattacks, says French Caldwell, a Gartner analyst with an extensive government background, including work with the Department of Defense. While he says he can't offer specific details of those simulations and who participated in them, he does say that the possibility had been considered that cyberterrorism could be used as "a distraction or precursor" to physical terrorist attacks. The link for this article located at PCWorld is no longer available. . Although there have been no reported cases of cyberterrorism or hacks of corporate or U.S. governmen. although, there, reported, cases, cyberterrorism, hacks, corporate, governmen. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.