According to the 2012 Independent Oracle User Group (IOUG), 28 percent of Oracle users have never applied a Critical Patch
Update or don’t know whether they’ve done so. Another 10 percent take a year or longer to apply their patches.2
It is common to find vulnerable and un-patched databases, or discover databases that still have default accounts and configuration
parameters. Attackers know how to exploit these vulnerabilities to launch attacks against your organization. Unfortunately,
organizations often struggle to stay on-top of maintaining database configurations even when patches are available. It generally
takes organizations months to patch databases once a patch is available. During the time your databases are un-patched, they
remain vulnerable