Study: Oracle database software has more flaws than SQL Server
Microsoft is often unfairly slammed for security issues, says NGSS
Computerworld - Microsoft Corp may be taking the most heat among software vendors for security problems, but it's not always the one with the worst record.
A comparison of vulnerabilities in Microsoft's SQL Server database with Oracle Corp.'s relational database management products by Next Generation Security Software Ltd. (NGSS) shows that the latter vendor's products to have far more vulnerabilities than do products from Microsoft.
Between December 2000 and November 2006, external researchers discovered 233 vulnerabilities in Oracle's products compared with 59 in Microsoft's SQL Server technology, according to NGSS, which has worked for Microsoft in the past to make its software products more secure. The study looked at vulnerabilities that were reported and fixed in SQL Server 7, 2000 and 2005 and Oracle's database Versions 8, 9 and 10g.
The results show that the reputation that Microsoft SQL Server had back in 2002 for relatively poor security is no longer deserved, said David Litchfield, founder of Surrey, England-based NGSS. And neither is the beating that Microsoft has gotten for security issues, he said.
"I think it's time people got past this, especially security researchers," Litchfield said. "We should be about closing holes and improving a vendor's outlook on security and -- largely -- that battle has been won with Microsoft," he said. The results show that Microsoft's software development life-cycle processes appear to be working, he said.
"There are other battles needing to be fought and won -- Oracle being one of them," Litchfield said.
In an e-mailed comment, an Oracle spokeswoman said the number of reported vulnerabilities in a product alone is not a measure of the overall security of that software.
"Products vary significantly in terms of richness of features and capabilities as well as number of versions and supported platforms," she said. "Measuring security is a very complex process, and customers must take a number of factors into consideration -- including use-case scenarios, default configurations as well as vulnerability remediation and disclosure policies and practices."
Basing a product's security just on the number of vulnerabilities discovered and fixed may not be the best approach, said Pete Lindstrom, an analyst at Midvale, Utah-based Burton Group. "Oracle apparently won an ugly contest," he said. But "there's got to be other criteria other than known vulnerabilities" for measuring software security, Lindstrom said.
Until then, Lindstrom said, "the jury should still be out on what's more or less secure."
The NGSS report comes at a time when security researchers, irked by what they consider to be Oracle's glacial pace of fixing bugs, are increasingly turning their attention to its products. In October, the company announced fixes for over 100 flaws as part of its scheduled quarterly security updates. Many of the flaws were reported to the company by outside researchers.
- Securing Mobile App Data - Comparing Containers and App Wrappers Analysts agree that Mobile Device Management (MDM) is not enough when it comes to securing app data. Although it remains a critical component...
- PCI 3.0 Compliance In this white paper, learn how PCI-DSS 3.0 effects how you deploy and maintain PCI compliant networks using CradlePoint devices.
- Mitigating Security Risks at the Networks Edge This white paper provides strategies and best practices for distributed enterprises to protect their networks against vulnerabilities, threats, and malicious attacks.
- 5 Strategies for Modern Data Protection Read the five strategies for modern data protection that will not only help solve your current data management challenges but also ensure that...
- Business-driven data protection Setting up data protection infrastructures with your organizations' core mission or business in mind is key. In this webinar, the ARCserve team will...
- On-Demand Webinar: Mind the Gap! Watch the webinar featuring Bob Janssen, CTO and Co-Founder of RES Software, to start building a solid foundation for business and IT to... All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!