Oracle RDBMS security patch reports

Apart from the use of costly commercial vulnerability scanners, are there easy techniques to produce a user-friendly management report on what security patches are missing from a server Oracle 11 g? Or better still to produce a 'fully patched security' type assurance to management report.

Could you provide some simple steps to make the report or management of a sample report?
In addition, that excuse my ignorance, but I've heard systems administrators say that they often fall security patches from database that they refer, apply the hotfix could cause problems with the operation of the application, it's a legitimate concern or a load of nonsense? Have you ever applied a security patch that had an unfortunate knock on effect on the request which it gives life.

Please keep simple answers to the DBA/management not friendly.

Hello

in my experience in customer support, I found that customers often confuse the severity of a vulnerability of security with the effects
correction, for example a typical vulnerability would involve validating the incorrect settings, so it would be possible to abuse an API
call to "do their thing", however well behaved applications never try to do more than documented, so for those the fix has zero effect.

Also in my experience regressions are very rare and even more exceptional in patches of CPU, since they do not plan to change the
feature but only to stop bad things or possible.

The best practice is to catch up with the CPU patches (or power supply) as they are made available and do not fall too far behind, each time as Oracle
emits an alert or quarterly a patch of CPU, there is a risk matrix that lists scores of vulnerability on a scale of 1 to 10
detailing how he is this time for the CPU quarterly most people forget that it only lists the problems reported since the previous.
then when they fall with wonder and patching, if the issue is serious enough to apply a patch for it, they forget to check
the severity of all issues fixed since the last CPU they applied.

The Advisor must simply apply these patches as soon as they are made available as they are low-risk and fix serious problems.

To check which hotfixes are installed in household use of database: opatch lsinventory-patch, for example with the last power supply on 11.2.0.3 it looks like this:

Patch 14727310 : applied on Wed Jan 16 08:11:22 THIS 2013
Patch ID: 15663328
Patch description: "Set update database: 11.2.0.3.5 (14727310).
Created on December 27, 2012 00:06:30 hrs PST8PDT
Sub -patch 14275605; "Game of the database update fixes: 11.2.0.3.4 (14275605).
Sub -patch 13923374; "Game of the database update fixes: 11.2.0.3.3 (13923374).
Sub -patch 13696216; "Game of the database update fixes: 11.2.0.3.2 (13696216).
Sub -patch 13343438; "Game of the database update fixes: 11.2.0.3.1 (13343438).
Bugs fixed:

Inside the database, you can query the registry history $ for example (for the same database):

SQL > set linesize 90
set pagesize 100
Select substr(action_time,1,30) action_time,
substr(ID,1,8) id,
substr action (action, 1, 10),
version of substr (version, 1, 8),
substr(BUNDLE_SERIES,1,6) BUNDLE_SERIES,
substr (Comments, 1, 20) comments
history of registry of $; SQL > SQL > 2 3 4 5 6 7

ACTION_TIME ID ACTION VERSION
-------------------- ---- -------- --------------------------------
BUNDLE_SERIES COMMENTS
------------------------ ----------------------------------------
10.21.11.5 17-SEP-11 0 TO APPLY 11.2.0.3
95816 AM
Group patches PSU 11.2.0.2.0

JULY 6, 12 02.11.35.3 0 IS APPLIED 11.2.0.3
33630:
Group patches PSU 11.2.0.2.0

20 NOVEMBER 12 04.55.45.3 4 TO APPLY 11.2.0.3
98041 PM
POWER SUPPLY PSU 11.2.0.3.4

16 JANUARY 13 08.13.40.6 5 IS APPLIED 11.2.0.3
13726 AM
POWER SUPPLY PSU 11.2.0.3.5

For more information, see:

notes 821263.1 How confirm that an update critical Patch (CPU) has been installed on Linux / UNIX

Greetings,

Damage ten Monkshood

Published by: hnapel on January 16, 2013 03:41

Tags: Database

Similar Questions

  • Diagnosis of Norton reports that 'key performance or security patches' lack of Vista

    Diagnosis of Norton report "key performance or security patches" are missing from my OS again Microsoft Windows Update has nothing

    * original title - setcurity performance or patches *.

    Hello

    as is Norton providing application support Norton report an explanation

    http://www.Symantec.com/support/index.jsp

    or try the norton forums

    http://community.Norton.com/

  • Oracle AWR and ADDM report for a multiple instance Oracle database 11 g 2 (RAC)

    Hello

    How to create an Oracle AWR and ADDM report for a multiple instance (RAC) Oracle database 11 g 2?

    Concerning

    Hello

    Oracle DB 11 g 2 AWR Global report before 11 GR 2, the awrrpt.sql generation

    under $ORACLE_HOME/rdbms/admin only generates the report awr for the local instance.

    You will need to collect for each RAC instance awr report.

    11 GR 2, there are two new scripts awrgrpt.sql AND awrgdrpt.sql for CARS

    awrgrpt. SQL - AWR Global report (RAC) (global report)

    awrgdrpt. SQL - overall Diff AWR (RAC) report.

    Some other important scripts under $ORACLE_HOME/rdbms/admin

    spawrrac. SQL - Server Performance RAC report

    awrsqrpt. SQL - statement of the standard ANSI SQL92 report

    awrddrpt. SQL - period diff on the current instance

    awrrpti. SQL - workload repository Instance (RAC) report

    REF link:

    ADDM enhancements in Oracle Database 11 g & mdash; DatabaseJournal.com

  • Y at - it a combo for 2016-001 updated security patch

    I try to install the security patch 2016 El Capitan-01 on the app store, but when the update try to restart, the restart just stops with the Finder running (I can Alt - TAB), but no other possibility of progress on reboot. I also downloaded the PACKAGE for the upgrade, but it has had the same impact.

    In the past, I worked around this problem by using a combination of upgrade (combo). He doesn't have one for this security patch.

    No guidance on problem (without own restart) or the other (combo) welcome.

    The only combo I know is:

    Download update of OS X El Capitan 10.11.6 Combo

    However, the Post Date: July 18, 2016

  • After the security patch - WMP 10 errors

    After you apply the security patch Windows Media 10 KB911565, Windows Media Player detects errors in playback of avi files (more precise: in quartz.dll module). All solutions?

    I n t still have a problem, but the fact is that quartz.dll file DirectX and you can find it in the Windows\System 32 folder. I put t know if this can help, but you can try to install the latest version of DirectX.

  • My laptop 1983 support Chrome with security patches?

    I received an email from Google saying that the platform used on my laptop will not be supported with security patches in the future. What is a problem for me? I have a 1983 (white!) with Mac OS X, Intel Core 2 Duo 2.26 GHz processor.

    You may hear 2003?  Or 2013?  There is no Mac 1983 with Intel chips. The answer to your question is 'no, and Google told you,' but I'm curious to know what you really there.

  • Latest security patch is causing my Sony Vaio to plant abruptly and not initialize.

    I settled on the recommended automatic so I was not really expected a nightmare when instead of clicking the close option as usual, I pressed the power option keys which allowed the last version of Windows including the new security patch must be installed updates to Windows. When I tried to power my laptop again once he would only start for a second before turning off suddenly. He did this several times with the switch off the coast so sudden that I first thought it was a question of power, but what repair Windows came, he had a well-posed power my first thought.  The first repair attempt has not fixed the problem then the laptop restart cut again randomly during the boot. After several attempts to turn on, Windows repair came on once again, but in this case after ten minutes of "trying to fix" she came back with the result that it could not. However, I had the opportunity to do a system restore that seems fortunately to have worked. I am however faced with the problem of Windows once more want me to update my system. After what happened before, I'm not want to do. Is there a way around this so that this update and patch will install not or that can be installed without the nightmare of him causing the laptop repeatedly crash after.

    Software operating is Vista.

    NOD32 or Eset Smart Security is installed? If Yes, then see - Microsoft security update for Windows 7 (KB2286198) crashes or causes a BSOD reboot
    Update the virus signatures database at 5338 or later before installing the update.

    If neither are installed, you run the Fixit who allows a work around for the vulnerability? If so, then run theFixit disable solution before installation KB2286198.

    MowGreen Services update - consumer safety

  • What is the link to the recent security patch that includes XP?

    I am a senior with XP, trying to find the real link with the recent security patch that includes XP.  Can someone send me the correct link? Thank you

    Thank you very much.  I was able to do according to your instructions. It's so complicated for a non-techie; no doubt that I would have never found without your help.

    I'm glad that worked for you!  I don't know if after you have installed this update if you need to restart or not. If she did not go to you, I do it anyway.

    Whenever I have uninstall or install anything, I always restart. Just a habit that I took some time ago.

    Have a nice weekend!!

    Thanks for your answer, too!

  • Error code: 0xf0f4 and the Windows XP KB2686509 security patch will not install.

    Original title: my PC won't install Windows XP Security patch KB2686509.

    My PC trying to install Windows XP Security patch KB2686509 daily from May 12, 2012 at each time get a 0xf0f4 error message. A lot of very complicated solutions offered on the keyboard files but nothing that a fan of the computer can understand.

    Please can you provide a simple solution to this problem!

    Here is the log:

    8.906: 19/08/2012 19:08:49.125 (local)
    8.906: C:\WINDOWS\SoftwareDistribution\Download\3438087687b5dd8accc81e44f72f02e7\update\update.exe (version 6.3.13.0)
    8.953: DoInstallation: GetProcAddress (InitializeCustomizationDLL) returned: 0x7f
    8.953: impossible to activate SE_SHUTDOWN_PRIVILEGE
    8.968: hotfix started with following command line: - q - z - er /ParentInfo:dfb5f7df1a6cfc4ab8379c8f32fdcb80
    9.093: in function GetReleaseSet, line 1211, RegOpenKeyEx failed with error 0x2
    9.093: in function GetReleaseSet, line 1240, RegOpenKeyEx failed with error 0x2
    12.093: Returns the value of IsMachineSafe = 0
    12.093: IsMachineSafe return 441092
    12.093: condition in Prereq.IsMachineSafe.Section failed with the fist
    12.109: Check condition for 1 line of prerequisite returned FALSE
    12.140: ReadStringFromInf: UpdSpGetLineText failed: 0xe0000102
    12.140: KB2686509 Setup has encountered an error: Setup cannot continue because one or more prerequisites required for the installation of KB2686509 failed. For more details, check the c:\windows\KB2686509.log log file
    12,156: ReadStringFromInf: UpdSpGetLineText failed: 0xe0000102
    12,156: Setup cannot continue because one or more prerequisites required for the installation of KB2686509 failed. For more details, check the c:\windows\KB2686509.log log file
    12,156: Update.exe extended error code = 0xf0f4

    Hi JohnWickenden

    You can read the following article and try the steps to correct known issues with this security update:

    http://support.Microsoft.com/kb/2686509

    Important: The above link contains steps to modify the registry. However, serious problems can occur if you modify the registry incorrectly. Therefore, make sure that you proceed with caution. For added protection, back up the registry before you edit it. Then you can restore the registry if a problem occurs.

    For more information, you can view the article:

    How to back up and restore the registry in Windows XP

  • Should I run F-secure and Microsoft security patches.

    Should I download the Microsoft security patches.  I have F-secure antivirus software on my computer and they said not to come in any other capacity.  I understand the issue of conflict, but I'm not computer savvy enough to know if it's antivirus protection that conflicts with F-secure or repairs for Microsoft software.  Thanks for your help!

    You should definitely download and install all the patches 'high priority' security offered by Windows Update or Microsoft Update.

    You must install not "optional" updates and do not have to install updates of hardware (drivers).  If you think always that you need to update a driver, get it on the site of the manufacturer of your computer (especially for laptops) or of the author of the particular piece of hardware.

    F-Secure advises (correctly IMO) that you don't have two active antivirus applications at the same time.  Security patches and one-off analyses (for example the monthly download of the Microsoft Malicious Software Removal Tool) do not appear in this caveat.

  • system of Comodo internet security keeps report this file as a Trojan horse, winlogon.exe

    Basically, whenever my computer is turned on and at different times of the day, my comodo internet security keeps report this file as a Trojan horse, press on to clean but always reports the same custom let me remove it so is it true or just a false positive to be added to my files of trust?

    Sometimes these sites to work, but they seem to be OK now (I just tried both).

    If your system seems to be starting and running OK and Comodo is complaining, it seems that your Comodo can be afflicted and considered a 'false positive '.  Make sure you have the latest version and definitions for your Comodo.

    If Comodo thinks the file is afflicted, and if you leave Comodo to delete the file, your system unbootable, and you will see a message like this on the next reboot:

    STOP: c000021a {fatal system error}
    The Windows logon process ended unexpectedly with the status of 0xc0000034 (0 x 0000000 0000000 x 0).
    The system has been shut down.

    It is usually not too difficult difficulty, but I would take measures to ensure that this never happens in the first place!

  • Security patches XP redirect to bad links.

    Original title: XP security patches

    All the XP security patches to the wrong download link. Is there a way to get around this?

    Specifically, http://www.microsoft.com/download/en/security.aspx?q=security&fs=operatingsystems ~ Pierce 255th % 2522Windows % 2520XP % 2522% 2524% 3bproducttype ~ 255th % 2522Security % 2520Patch % 2522% 2524 & p = 4 & r = 50 & t = 1668 & s = availabledate ~ descending

    Hello

    I tried to download the security patches from the link you provided and they open the correct link, you can try to open the links once more and check if the problem persists.

  • Security patches

    I have 2009 security patches. Can I uninstall them? Haven't they been replaced by new versions with the included patch?

    Hello

    They have not been replaced.

    No.; you do not uninstall them. As you do not exactly give the date of 2009, they were probably released after the release of Vista SP2.

    If uninstall you, you will lose the security and Preformance improvements they give to your operating system.

    See you soon.

  • The error message is im like error: 0xC004D401 Description: the security processor reported a system file mismatch error. After doing the update of windows Vista.

    There is a problem with your license so notifications will no longer appear
    You will no longer receive communications, including those concerning your license or activation.
    To try and fix this problem click on one of the links below.
    Error: 0xC004D401
    Description:
    The security processor reported a system file mismatch error.

    Vista Service Pack 2 (SP2) is installed?

    ==========================

    1. Download this diagnostic tool, save it to your desktop, then right click on the saved file and select run as administrator to run the utility: http://go.microsoft.com/fwlink/?linkid=56062

    2. once the race completed, click the continue button, and then click the copy button (on the Clipboard).

    Note: You can open a new file in Notepad, paste the contents of the Clipboard in it & keep for future reference.

    3. start your own, new thread in the following Microsoft Genuine Advantage forum and paste the results of the diagnosis of MGA tool in your post, and a clear description of your problem:

    http://social.Microsoft.com/forums/en-us/genuinevista/threads

    4 Troubleshooting specialist will analyze the data and recommend an appropriate solution.

  • Last update and security patch is causing my Sony Vaio suddenly Crash

    0
    I settled on the recommended automatic so I was not really expected a nightmare when instead of clicking the close option as usual, I pressed the power option keys which allowed the last version of Windows including the new security patch must be installed updates to Windows. When I tried to power my laptop again once he would only start for a second before turning off suddenly. He did this several times with the switch off the coast so sudden that I first thought it was a question of power, but what repair Windows came, he had a well-posed power my first thought.  The first repair attempt has not fixed the problem then the laptop restart cut again randomly during the boot. After several attempts to turn on, Windows repair came on once again, but in this case after ten minutes of "trying to fix" she came back with the result that it could not. However, I had the opportunity to do a system restore that seems fortunately to have worked. I am however faced with the problem of Windows once more want me to update my system. After what happened before, I'm not want to do. Is there a way around this so that this update and patch will install not or that can be installed without the nightmare of him causing the laptop repeatedly crash after.

    Change the way you receive updates:

    http://www.bleepingcomputer.com/tutorials/tutorial140.html

    Understand the Extras in Windows Vista and Windows Update info is at the link above.

     

    Remove the Vista updates; two ways to do this:

    1. a System Restore to before the updates:

    Click Start > programs > Accessories > system tools > System Restore > restore time/choose your own date > next

    If you use Norton, disable it before using the system restore.

    If it is impossible to enter the Normal Mode, do a Safe Mode system restore:

    Press F8 at the startup/power and the list of startup options, use THE ARROW key to select Safe mode > and then press ENTER.

    System restore steps according to the info above.

    Also:

    2. click on start > right click on computer > properties > Windows updates down the lower left corner > updates installed in the lower left corner in the next window

    > then click the one that you don't want > uninstall will appear at the top > uninstall it.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    In addition, on the page where you clicked "Installed updates", click on change settings at the top left corner it

    > Change update settings in the next page of AutoUpdate to "check for updates but let me choose etc" > OK ".

    When you take a look at pending updates, you can either download/install them one at the time, namely the update causing you problems.

    > or if you do not need an individual > right-click on > UAC prompt > hide it

    See you soon.

    Mick Murphy - Microsoft partner

Maybe you are looking for