Question

Case Project 3 - 1: Determining Vulnerabilities for a Database Server You have interviewed Ms. Erin...

Case Project 3 - 1: Determining Vulnerabilities for a Database Server You have interviewed Ms. Erin Roye, an IT staff member, after conducting your initial security testing of the Alexander Rocco Corporation. She informs you that the company is running Oracle 10g for its personnel database. You decide to research whether Oracle 10g has any known vulnerabilities that you can include in your report to Ms. Roye. You don’t know whether Ms. Roye has installed any patches or software fixes; you simply want to create a report with general information. Based on this information, write a memo to Ms. Roye describing any CVEs (common vulnerabilities and exposures) or CAN (candidate) documents you found related to Oracle 10g. (Hint: A search at US-CERT, www.us-cert.gov, can save you a lot of time.) If you do find vulnerabilities, your memo should include recommendations and be written in a way that doesn’t generate fear or uncertainty but encourages prudent decision making.

0 0
Add a comment Improve this question Transcribed image text
Answer #1

Here's your answer:

Hello Erin,

I hope you are doing well. After conducting the security analysis on the database Oracle 10g that currently Alexander Rocco Corporation is using, I found there are many security vulnerabilities not addressed at all. I would like to bring this to your notice. There are total number of 24 detected security vulnerabilities in Oracle 10g. Some security threats have been not disclosed publicly and some vulnerabilities have been disclosed. Among 24 security threats, I would like to discuss few important threats that Alexander might face based on the current scenarios.

  • Vulnerable Java Script code can be injected through Cross Site Scripting (XSS)
  • Excess privileges to the local user(s) who have only SELECT privilege when they create crafted VIEW.
  • SQL injection by remote hackers
  • Getting access only with valid username in Windows XP file shared system.
  • Buffer Overflow attack through SDO_CODE_SIZE

It is the need of the hour that these security vulnerabilities have been addressed at the earliest at Alexander to protect user(s) and company’s confidential data by upgrading to the latest code base.

Thank you

Add a comment
Know the answer?
Add Answer to:
Case Project 3 - 1: Determining Vulnerabilities for a Database Server You have interviewed Ms. Erin...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT