10.9.07

Oracle software implementation helps police deal with enquiries

A software implementation from Oracle has helped Dubai Police significantly speed up its operations, a senior official from the force said today.

Speaking a press conference at the GITEX Technology Week trade show, Colonel Ahmed Hamdan Bin Dalmook, manager e-services department, Dubai Police, told attendees that Dubai Police's deployment of an electronic messaging system from Oracle had enabled it to substantially improve its response times, operational performance and efficiency of transactions.

The software giant built a robust foundation to automate and streamline Dubai Police's messaging processes using its Oracle Database software.

The system, which is now used by more than 5000 people in Dubai Police, replaced the previous manual transmission of documents between departments and external entities.

The Oracle solution enabled correspondence and documents to be organized and available on demand as searchable content, with the integration of e-mail and fax resulting in faster response times and more efficient operations.

"In line with Dubai Government's e-government initiative, Dubai Police had a strategic need to migrate toward an enterprise-level IT infrastructure to enhance productivity and streamline operations," said Hamdan Bin Dalmook.

"We wanted to organize and automate our daily correspondence, and align our business processes between departments," he added.

"Oracle has developed a superior and secure database offering which is ideal for government organizations and addressed our critical requirements around data privacy and protection, regulatory compliance and data consolidation," he went on to say.

Oracle also supplied Dubai Police with a unified architecture and repository for managing internal and external documents and files.

Dubai Police was the first government department in the region to implement the units from Oracle, Bin Dalmook added.

Author: Michele Howe


Read more ...

7.9.07

Expert finds 'stupid' holes in Oracle 11g

Architectural problems, one researcher says, let attackers 'bypass and avoid' Oracle's newest security tools. The latest version of Oracle's flagship database offers better security than earlier versions, but development errors have left vulnerabilities that attackers can use to steal data, an expert warned Monday.

"Oracle made big progress with 11g, but some of the vulnerabilities I've found so far in 11g are stupid programming errors," said Alexander Kornbrust, managing director of Red Database Security GmbH, during an interview at the Hack In The Box (HITB) Security Conference 2007 in Kuala Lumpur, Malaysia.

"Oracle must educate their own development team because they should normally avoid these simple security vulnerabilities," Kornbrust said.

Oracle executives were not immediately available for comment.

Kornbrust, who helps large companies audit the security of their Oracle databases, examined the software and found SQL injection vulnerabilities, which allow attackers to run malicious code. He also uncovered a way to circumvent the auditing capability in 11g and other versions of the database, which could undermine a company's compliance efforts.

While Kornbrust plans to discuss some Oracle vulnerabilities at HITB, he has no plans to detail his method for bypassing the auditing capability until Oracle has fixed the problem.

Some of the problems that Kornbrust uncovered reflect architectural problems with Oracle's database. In a talk scheduled for later this week, he plans to demonstrate how architectural problems allow attackers to "bypass and avoid" Oracle's latest security tools, including Oracle Database Vault and Oracle Audit Vault.

The cost and time required to fix a vulnerability in Oracle's database can be staggering because of the critical role the software plays in the business of large companies, and the wide range of platforms that Oracle supports, Kornbrust said.

Citing the example of one German company that has 8,000 Oracle databases, Kornbrust said rolling out a single patch can require 32,000 hours of labor, or four hours per database. That translates into 60 full-time database administrators and doesn't take into account the time and expense required for testing the patch on each database, he said.

Moreover, for each vulnerability that gets patched, Oracle must develop a patch for every version of its database that's supported, with a version of each for every hardware platform and operating system the database runs on. That amounts to around 100 separate patches for every vulnerability, Kornbrust said.

Author: Sumner Lemon


Read more ...

6.9.07

Oracle Opens Nominations for Oracle Innovation Award

REDWOOD SHORES, Calif., Sept. 6 /PRNewswire-FirstCall/ -- Oracle today announced the call for nominations for the Oracle Innovation Award. Co-sponsored by the Oracle Applications User Group (OAUG) and Quest International Users Group (Quest), the Oracle Innovation Award is designed to recognize organizations that are extending the business value of their Oracle(R) Applications with Oracle Fusion Middleware as a result of Oracle's "Applications Unlimited" program.

Customers throughout the world can submit nominations between now and Oct. 5, 2007, to showcase their innovation with Oracle Fusion Middleware and Oracle Applications including the Oracle E-Business Suite, Oracle's PeopleSoft Enterprise, Oracle's JD Edwards EnterpriseOne and Oracle's Siebel CRM applications. To qualify, organizations must be using at least one component of Oracle Fusion Middleware, at least one Oracle Application and have the solution in production or in active development. 25 winners will receive a conference pass to Oracle OpenWorld(R) San Francisco 2007, with access to the Global Customer Program lounge and a one-on-one conversation with an Oracle executive at an award reception scheduled to take place at the event. In addition to these prizes, the top five winners will also receive one Oracle OpenWorld San Francisco 2007 conference pass with a Club Oracle Gold upgrade; will be featured in a cover story article alongside their systems integrator partner (if applicable) in Oracle's Profit magazine; and will have an exclusive appearance on Oracle's podcast
series, Appcast.(i)

"Oracle Fusion Middleware's hot-pluggable architecture and portfolio of best-in-class middleware components enable customers of any size to increase the value of their applications across user communities, lines of business and organizations," said Amit Zavery, vice president, Oracle Fusion Middleware Product Management, Oracle. "While customers experience substantial benefits from using Oracle Fusion Middleware with Oracle Applications, the Oracle Innovation Award gives us the opportunity to publicly commend and reward organizations for their particularly innovative use of these offerings."

"As a result of our Applications Unlimited program, many of our customers are evolving their existing Oracle Applications to leverage next-generation technology such as Service-Oriented Architectures and Web 2.0 design principles," said Evelyn Neumayr, vice president, Applications
and Industries Marketing. "The Oracle Innovation Award will highlight these customers for their work in this area and will serve as excellent examples for organizations that are currently seeking ways to drive added value from their applications investments."

Selecting the Winners

The Award Selection Committee, consisting of individuals from Oracle, OAUG and Quest, will select the winners based on factors including the level of impact relative to the size of the organization, complexity of the implementation and future plans. Winners will be notified of their
successful submission by Monday, Oct. 15, 2007, and will be publicly announced at Oracle OpenWorld San Francisco the week of Nov. 12, 2007. For additional information regarding this award please visit: http://www.oracle.com/applications/oracle-innovations-award.html.

Source: PRNewswire


Read more ...