You have interviewed Ms. Erin Roye, an IT staff member, after conducting your in
ID: 3913983 • Letter: Y
Question
You have interviewed Ms. Erin Roye, an IT staff member, after conducting your initial security testing of the Alexander Rocco Corporation. She informs you that the company is running an older version of Oracle’s database, Oracle 10g, for its personnel database. You decide to research whether Oracle 10g has any known vulnerabilities that you can include in your report to Ms. Roye. You don’t know whether Ms. Roye has installed any patches or software fixes; you simply want to create a report with general information. Based on this information, write a memo to Ms. Roye describing any CVEs (common vulnerabilities and exposures) or CAN (candidate) documents you found related to Oracle 10g. (Hint: A search of the CVE Web site sponsored by US-CERT, https://cve.mitre.org/, can save you a lot of time.) If you do find vulnerabilities, your memo should include recommendations and be written in a way that doesn’t generate fear or uncertainty but encourages prudent decision-making.
Explanation / Answer
Memo:
Mr. Jones,
It was an immense pleasure to meet your staff today and was great to discuss with them the various aspects of the state of the cybersecurity at Alexander Rocco Corporation. After listening carefully to all the discussion today I am certainly relating some of the challenges that your staff is been facing in the Oracle Technologies you are having in your company for the employee use.
I have found some of the serious vulnerabilities in the oracle 10g the version your company is been using. Some of the serious vulnerability are CVE-2007-3856(REMOTE AUTHENTICATION ATTACK) & CVE-2006-6703(XSS). There are some simple methods through which one can setup this completely with no worries of getting system hanged up with these kinds of vulnerablities. Thus, these are some important things to notice in the oragcle 10g.
Hence ,this is the memo for the above situation.
Related Questions
drjack9650@gmail.com
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.