Security Market Segment LS
Friday, 22 November 2019 10:18

Oracle EBS flaws leave customers open to ERP system hacks

By
Oracle EBS flaws leave customers open to ERP system hacks Image by mohamed Hassan from Pixabay

Database vendor Oracle's E-Business Suite is at risk due to vulnerabilities discovered in December last year, and which could give attackers full control over a company's enterprise resource planning solution.

Collectively called PAYDAY, the flaws were found by Onapsis Research Labs and patches were initially issued by Oracle in April 2018. Subsequent flaws were patched a year later.

However, at this stage, about 21,000 Oracle EBS customers are estimated to be at risk since the PAYDAY flaws exist in all versions of the software, Onapsis researcher Sebastian Bortnik said in a blog post.

"The severity... is evident from the significance of ERP systems such as Oracle to global business function; 77% of global revenue will pass through an ERP system at some point, of which Oracle’s 21,000 EBS customers are just a proportion," Bortnik said.

"These vulnerabilities can only be mitigated by applying security patches. Onapsis estimates that 50% of Oracle EBS customers have not deployed the patches."

In a detailed report on the flaws, Onapsis said leaving them unaddressed could also mean that companies did not meet compliance standards required by different countries.

"From a Data Privacy standpoint (GDPR, CCPA, HIPAA, etc.), this vulnerability could allow an attacker to get personally identifiable information (PII) from the systems. This is the type of risk that usually makes executives and boards concerned about the possibility of a breach and a subsequent penalty if not properly addressed," the Onapsis report said.

Commenting on the vulnerabilities, Piyush Pandey, chief executive of ERP data security vendor Appsian, said: “Unfortunately, hackers are aware that traditional ERP systems lack the granular logging and analytics features required to detect unauthorised activity.

"Having a vulnerability that exploits a customer who may not be current on their security updates raises the risk of a data breach exponentially. Organisations must take additional steps to enhance their levels of visibility and control over their ERP data - and all of the user activity taking place around it."

Update, 25 November: Contacted for comment, Eric Maurice Oracle senior director, Global Product Security, said: “The security issues discussed in this paper have all been addressed in Oracle’s Critical Patch Update. Oracle encourages customers to follow the secure configuration recommendations in its deployment guides, remain on actively-supported versions, and apply Critical Patch Updates without delay.

"Unfortunately, Oracle continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches. In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches.

"At the time of the publication of this report, the most recent Critical Patch Update was the October 2019 Critical Patch Update."

Read 2973 times

Please join our community here and become a VIP.

Subscribe to ITWIRE UPDATE Newsletter here
JOIN our iTWireTV our YouTube Community here
BACK TO LATEST NEWS here




IDC WHITE PAPER: The Business Value of Aiven Data Cloud Solutions

According to IDC, Aiven enables your teams to perform more efficiently, reduce direct infrastructure costs, and provide improved database performance, agility and scalability.

Find out how Aiven makes teams 48% more efficient, allowing staff to focus on high-value activities that drive real business results:

340% 3-year ROI – break even in 5 months (average)

37% lower 3-year cost of operations

78% reduction in staff time for database deployments


Download the IDC White Paper now

DOWNLOAD WHITE PAPER!

PROMOTE YOUR WEBINAR ON ITWIRE

It's all about Webinars.

Marketing budgets are now focused on Webinars combined with Lead Generation.

If you wish to promote a Webinar we recommend at least a 3 to 4 week campaign prior to your event.

The iTWire campaign will include extensive adverts on our News Site itwire.com and prominent Newsletter promotion https://itwire.com/itwire-update.html and Promotional News & Editorial. Plus a video interview of the key speaker on iTWire TV https://www.youtube.com/c/iTWireTV/videos which will be used in Promotional Posts on the iTWire Home Page.

Now we are coming out of Lockdown iTWire will be focussed to assisting with your webinars and campaigns and assistance via part payments and extended terms, a Webinar Business Booster Pack and other supportive programs. We can also create your adverts and written content plus coordinate your video interview.

We look forward to discussing your campaign goals with you. Please click the button below.

MORE INFO HERE!

BACK TO HOME PAGE
Sam Varghese

Sam Varghese has been writing for iTWire since 2006, a year after the site came into existence. For nearly a decade thereafter, he wrote mostly about free and open source software, based on his own use of this genre of software. Since May 2016, he has been writing across many areas of technology. He has been a journalist for nearly 40 years in India (Indian Express and Deccan Herald), the UAE (Khaleej Times) and Australia (Daily Commercial News (now defunct) and The Age). His personal blog is titled Irregular Expression.

Share News tips for the iTWire Journalists? Your tip will be anonymous

Subscribe to Newsletter

*  Enter the security code shown:

WEBINARS & EVENTS

CYBERSECURITY

PEOPLE MOVES

GUEST ARTICLES

Guest Opinion

ITWIRETV & INTERVIEWS

RESEARCH & CASE STUDIES

Channel News

Comments