Security Blogs
20 Years of Securing Data in Oracle Databases
Posted by Pete On 09/02/23 At 10:48 AM
Looking for GRANT ALL on objects
Posted by Pete On 21/10/22 At 10:14 AM
Adding Scripting Languages to PL/SQL Applications - Part 1
Posted by Pete On 30/09/22 At 12:49 PM
Granting ALL on Database Objects
Posted by Pete On 09/08/22 At 12:46 PM
Do You Worry Your Companies data is Being Stolen?
Posted by Pete On 05/08/22 At 12:47 PM
Searchlight a Product to Make Finding Data Easy
Posted by Searchlight On 29/07/22 At 11:22 AM
Oracle Security - Hidden Grant When Create a Role and Revoke in a CDB
Posted by Pete On 07/06/22 At 10:31 AM
Adaptive Database Auditing and Security
Posted by Pete On 25/05/22 At 07:38 PM
The challenges of securing data in an Oracle database
Posted by Pete On 11/05/22 At 10:04 AM
Add License Checks Anywhere in your PL/SQL
Posted by PFCLObfuscate On 30/03/22 At 05:31 PM
Software from Building Blocks - Fast Development - One Month Projects
Posted by Pete On 22/03/22 At 06:33 PM
Make Pete Finnigan a remote expert part of your team
Posted by Pete On 10/03/22 At 01:40 PM
Do we Need to Revoke PUBLIC from a User?
Posted by Pete On 02/03/22 At 02:37 PM
Strong Passwords with Oracle Wallets
Posted by Pete On 23/02/22 At 02:01 PM
How I Write an Oracle Security Training Course
Posted by Pete On 15/02/22 At 11:17 AM
Happy 19th Birthday PeteFinnigan.com Limited
Posted by Pete On 12/02/22 At 09:50 AM
Pete, Did You Deliver The Wrong Product?
Posted by PFCLScan On 10/02/22 At 02:21 PM
How do we Train Staff to do Oracle Security?
Posted by Pete On 08/02/22 At 02:21 PM
Looking Forwards To 2022!!
Posted by Pete On 03/02/22 At 02:13 PM
Log4j Vulnerabilities Impact On Oracle E-Business Suite - Updated Information
Multiple significant security vulnerabilities (CVE-2021-44228, CVE-2021-45046, and CVE-2021-4104) have been disclosed and patched in the popular Java logging library Apache Log4j. This library is installed in Oracle E-Business Suite (EBS) environments and these vulnerabilities may be exploitable in your environment depending on Oracle EBS version, Oracle EBS patches applied, and customizations or third-party products.
On December 15th, Oracle has changed the remediation with the disclosure of the most recent Log4j security vulnerability (CVE-2021-45046) as the initial recommended fix was not complete.
Integrigy has completed a detailed analysis on the impact of these Log4j security vulnerabilities on Oracle E-Business Suite and you can access this analysis here -
Integrigy Log4j Vulnerabilities Impact on Oracle E-Business Suite Analysis
Integrigy's products AppDefend and AppSentry does not use the Log4j library, therefore, are not vulnerable to this security bug.
Please let us know if you have any questions regarding this security vulnerability at info@integrigy.com.
Pages
