Skip the navigation
)
News

The Oracle flaw: Clarifications and more information

In the wake of InfoWorld's exclusive story on a flaw in Oracle's flagship database product, Oracle weighs in and new developments emerge

By Paul Venezia, Eric Knorr
January 23, 2012 12:32 PM ET

InfoWorld - Since InfoWorld published "Fundamental Oracle flaw revealed" on Jan. 17, we've received abundant feedback from Oracle users and consulted with Oracle representatives, who went through the story point by point, offering clarifications and additional details, including information about the patches that address the flaw.

Moreover, recognized Oracle expert Riyaj Shamsudeen, president of the database services company OraInterals, has zeroed in on another aspect of the flaw in a Jan. 20 post entitled "SCN -- What, why, and how?" Shamsudeen notes that he had held off posting the blog entry "for many months." In a reference to InfoWorld's article, he adds: "Since this issue is in the public knowledge domain, I can share the knowledge without any repercussions."

[ See the original story, "Fundamental Oracle flaw revealed," which includes clarifications and additional information. | Also see Editor in Chief Eric Knorr's message to the Oracle community: "Calling all Oracle customers." ] 

Before we address this new development, a quick recap of where things stand: Oracle has acknowledged that InfoWorld uncovered undocumented, manual methods to raise the Oracle SCN (System Change Number) -- a sort of "time stamp" for every Oracle transaction -- which could cause an Oracle database to hit the SCN limit and cease to function properly. Oracle also corroborates another key point in the story: that elevated SCN values can be passed among Oracle databases, so that in heavily linked environments, those values may spread quickly.

But with steadfast consistency, Oracle has characterized the risk posed by these problems as minimal. In a conversation several days after publication, Oracle's Mark Townsend, vice president of database product management, told InfoWorld that the hot-backup bug described in the story was, in all likelihood, the only way Oracle Database systems might reach the SCN limit. (That bug is confined to Oracle Database 11g releases 11.1.0.7 and 11.2.0.2 and is listed as 12371955: "High SCN growth rate from ALTER DATABASE BEGIN BACKUP in 11g.")

Since our last conversation with Oracle, however, we have discovered a new method by which the SCN might be manually elevated -- and have received corroboration for an additional scenario we could only speculate about until Shamsudeen confirmed it in his post.

SCN rising: Two new possibilitiesFrom the outset, InfoWorld has made a clear distinction between two aspects of the Oracle flaw: Manual methods by which a bad actor might raise the SCN value of a database and cause it to hit the limit -- and organically elevated SCN numbers that occur through a bug such as the hot backup bug. Both cases can result in extreme SCN value increases among interconnected databases.

Originally published on www.infoworld.com. Click here to read the original story.
Reprinted with permission from InfoWorld. Story copyright 2012 InfoWorld Media Group, Inc. All rights reserved.
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

BI and Analytics White Papers
Thinking Outside The Data Warehouse
This high level, business problem focused eBook uses 5 customer scenarios to show how people and organizations are tackling real issues using IBM...
Using BD for Smarter Decision Making
This paper looks at new developments in business analytics and discusses the benefits analyzing big data bring to the business.
Measuring the Business Value of CI in the Data Center
One of the key strategies that IT teams are pursuing to reduce capital costs while boosting asset utilization and employee productivity is the...
Switching Schedulers - Not As Complicated As You Think
Changing or consolidating job schedulers may seem daunting. However, the benefits of switching to enterprise workload automation outweigh the risks. Read how BMC...
Capture-Enabled Business Process Management
Organizations today must deal with a vast amount of incoming information from many different sources. Efficient, automated business processes are critical to managing...
All BI and Analytics White Papers
BI and Analytics Webcasts
InfoSphere Warehouse Packs Demo
These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
Delivery Management -- Extending Lifecycle Management
Date: Wednesday, June 20, 2012, 1:00 PM EDT

Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
Leverage automation today to reduce IT complexity
Date: Tuesday, June 5, 2012, 2:00 PM EDT

Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific...
BMC Control-M - Single Point of Control Demo
With BMC Control-M, you schedule and manage everything - down to the very last platform and application - from one simple interface. It's...
BMC Control-M - Single Point of Control Demo
With BMC Control-M, you schedule and manage everything - down to the very last platform and application - from one simple interface. It's...
All BI and Analytics Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs