UPDATED 13:31 EDT / JANUARY 21 2015

Oracle Founder Larry Ellison NEWS

No, it’s not a typo: Oracle plugs a record 167 security holes

Oracle Founder Larry Ellison

Oracle rolled out a mammoth batch of patches on Tuesday in the first of four annual security fixes for its vast array of enterprise software products. What makes the otherwise routine update stand out is the sheer number of vulnerabilities addressed: a company-record 167.

One flaw that drew an outsized amount of attention is a misconfiguration affecting the enterprise technology stalwart’s popular E-Business Suite, which “gobsmacked” its discoverer, in his own words. David Litchfield, a U.K.-based expert on database security who is credited with uncovering hundreds of flaws, initially mistook the issue for a backdoor left behind by an hacker when he first spotted it while evaluating the defenses of a client.

Apparently, the default settings of the software gave users with the lowest level of authorization the ability to manipulate DUAL structure in the supporting Oracle database, a placeholder table that serves as a sort of built-in workaround for the limitations of SQL. It provides a straightforward way to execute commands that don’t require manipulating a specific piece of application data, such as determining the system date or checking account details.

But despite its innocuous applications, DUAL represents a massive target for hackers since it’s part of the data dictionary that keeps track of the information stored in relational tables. That means that a malicious party can take advantage of the vulnerability to execute a function against the table with full access privileges, laying the database bare for attack.

The most shocking part of the discovery is that such a conspicuous vulnerability passed Oracle’s quality assurance process, which Litchfield indicated should have been able to easily pick up on the issue as easily as he did and potential hackers might. While the misconfiguration still ranked fourth from last in Oracle’s rating of the severity of the exploits addressed in the update, it was notable for being so obvious.

The Oracle Sun Systems Products Suite shared the top spot with Java, which has a long history of vulnerabilities that has earned it a fair amount of criticism in the development community. The company assigned both flaws the highest possible rating on the CVSS v2 threat index, which means that they’re exploitable from outside the corporate network without the need for any kind of authentication.

U.S. Army Corps of Engineers photo

A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.