Data Loss Prevention

 View Only
  • 1.  Oracle Database Multiple Vulnerabilities (July 2017 CPU) (POODLE) (SWEET32)

    Posted Sep 11, 2017 01:52 PM

    Where can I find the Oracle Fix \ Download for this vulnrability ?  We have the Oracle Licenses through Symantec 

    Oracle Database Multiple Vulnerabilities (July 2017 CPU) (POODLE) (SWEET32)

    Synopsis

    The remote database server is affected by multiple vulnerabilities.

    • Description

      The remote Oracle Database Server is missing the July 2017 Critical Patch Update (CPU). It is, therefore, affected by multiple vulnerabilities :

      - A man-in-the-middle (MitM) information disclosure vulnerability, known as POODLE, exists due to the way SSL 3.0 handles padding bytes when decrypting messages encrypted using block ciphers in cipher block chaining (CBC) mode. A MitM attacker can decrypt a selected byte of a cipher text in as few as 256 tries if they are able to force a victim application to repeatedly send the same data over newly created SSL 3.0 connections.
      (CVE-2014-3566)

      - A vulnerability exists, known as SWEET32, in the 3DES and Blowfish algorithms due to the use of weak 64-bit block ciphers by default. A man-in-the-middle attacker who has sufficient resources can exploit this vulnerability, via a 'birthday' attack, to detect a collision that leaks the XOR between the fixed secret and a known plaintext, allowing the disclosure of the secret text, such as secure HTTPS cookies, and possibly resulting in the hijacking of an authenticated session.
      (CVE-2016-2183)

      - An unspecified vulnerability exists in the RDBMS Security component that allows a local attacker to impact integrity. Note that the attacker would need to have Create Session or Select Any Dictionary privileges.
      (CVE-2017-10120)

      - An unspecified vulnerability exists in the OJVM component that allows an authenticated, remote attacker to impact confidentiality, integrity, and availability.
      Note that the attacker would need to have Create Session or Create Procedure privileges. (CVE-2017-10202)

    • Solution

      Apply the appropriate patch according to the July 2017 Oracle Critical Patch Update advisory.



  • 2.  RE: Oracle Database Multiple Vulnerabilities (July 2017 CPU) (POODLE) (SWEET32)

    Trusted Advisor
    Posted Sep 12, 2017 05:06 AM

    Alfred,

    Go to www.fileconnect.symantec.com

    You will need the licesne key that you had with purchase of the DLP and Oracle platform.

    If you do not know this Serial number, you can possibly find it on the Enforce Server. Look in SymantecDLP\Protect\License

    Open up the slf file and you will see a number that typically starts with the Letter "M"

    Use that as the Serail Number on the above website. Hopefully you purchased DLP and Oracle at the same time and you shuld  be able to see all of the DLP binaries and also the Oracle ones too

     

    Good Luck

    Ronak

    PLEASE MARKED SOLVED WHEN POSSIBLE



  • 3.  RE: Oracle Database Multiple Vulnerabilities (July 2017 CPU) (POODLE) (SWEET32)

    Posted Sep 12, 2017 10:58 AM

    Ronak,

     

    I did go to the download page - www.fileconnect.symantec.com  there are NO Oracle fixes download files for my DLP system there ?

    where can i get the Oracle fix for July for my Symantec Oracle install? I already installed the DLP Server in April and I need JUST the Oracle vulnrability fix for July.



  • 4.  RE: Oracle Database Multiple Vulnerabilities (July 2017 CPU) (POODLE) (SWEET32)

    Trusted Advisor
    Posted Sep 12, 2017 01:17 PM

    If you go to the Symantec Page for License Maintenance you should be able to find the licesne key for Oracle.

     

    Good Luck

    Ronak

    PLEASE MARKED SOLVED WHEN POSSIBLE



  • 5.  RE: Oracle Database Multiple Vulnerabilities (July 2017 CPU) (POODLE) (SWEET32)

    Posted Oct 16, 2017 01:09 PM

    Ronak,

    I downloaded and isnatlled the Symnatec file (Oracle_11.2.0.4.0_CPU2017JUL_Win64) and it seem to deal with a different OJVM

    The missing OJVM Patches required is  26182425