
Published 17th July 2008
Application Security, Inc.’s SHATTER Team Credited with Discovering Four of 11 Vulnerabilities...
LONDON, July 16, 2008 ─ Application Security, Inc., the leading provider of database security solutions for the enterprise, today announced its support for the July Oracle CPU (critical patch update). The latest CPU includes 11 security fixes for the Oracle Database, none of which are remotely exploitable without authentication. Application Security’s, Inc. support of and contribution to this latest CPU further validates its position as an industry leader in the security space and as the only database security company to consistently provide complete protection through automatic updates to its database security suite, DbProtect™.
Security vulnerability researcher Esteban Martinez Fayo of Application Security Inc.’s Team SHATTER (Security Heuristics of Application Testing Technology for Enterprise Research), the industry’s most recognised database vulnerability research team, has been credited by Oracle for contributing to vulnerability discovery in this latest CPU. Fayo has also previously been recognised by Oracle as the first external researcher to not only discover vulnerabilities but also to collaborate with their internal team to ensure that customers receive a working fix of the “highest quality.”
“Effective database security requires a deep knowledge not only of vulnerabilities but also the database functions they’re associated with in the context of the underlying platform,” said Toby Weiss, president and CEO, Application Security, Inc. “Customers rely on DbProtect because it provides comprehensive database protection, which is continuously updated based on our world-class SHATTER research. It’s an honour that SHATTER is regularly credited by vendors like Oracle and that we’re able to work so well together to the benefit of the industry.”
More information on the latest Oracle CPU is available at: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html.
As with previous Oracle CPU’s, Application Security, Inc. will update its flagship DbProtect™ database security suite with the appropriate scanning checks and monitoring filters through its monthly ASAP Update™ (Application Security Automatic Protection). Updates to DbProtect for these vulnerabilities will include monitoring filters and scanning checks. The monitoring filters, which will be available in a few weeks, will allow customers to protect themselves during the deployment of the new patch across their database infrastructure. DbProtect scanning checks will be available shortly thereafter.
Built on the industry’s most extensive knowledge-base of database-specific vulnerabilities, DbProtect is acknowledged as the industry’s most complete database security solution - combining database discovery, scanning, vulnerability assessment, real-time activity monitoring and auditing. The comprehensive, integrated solution allows organizations to secure their most sensitive data from internal and external threats, while also ensuring that those organizations meet or exceed regulatory compliance and audit requirements.
More information on Application Security, Inc.’s ASAP Updates can be found at: http://www.appsecinc.com/asap/updates/.