7. Exploitation of Vulnerable, Misconfigured Databases
It is common to find vulnerable and un-patched databases, or discover databases that still have default accounts and configuration
parameters. Attackers know how to exploit these vulnerabilities to launch attacks against your organization. Unfortunately,
organizations often struggle to stay on top of maintaining database configurations even when patches are available. Typical
issues include high workloads and mounting backlogs for the associated database administrators, complex and time-consuming
requirements for testing patches, and the challenge of finding a maintenance window to take down and work on what is often
classified as a business-critical system. The net result is that it generally takes organizations months to patch databases, during which
time they remain vulnerable.
According to the 2014 Independent Oracle User Group (IOUG) Enterprise Data Security Survey, 36 percent of Oracle users take more
than six months to apply a Critical Patch Update, while another 8 percent have never applied one.