11.1.08

Oracle Plans To Patch 21 Security Holes Next Week

Oracle's January patch contains significantly fewer fixes than in previous quarters. In October, the company released 51 fixes; in July, it released 45.

Oracle (NSDQ: ORCL) plans to release a Critical Patch Update for its products on Jan. 15. The patch corrects vulnerabilities in multiple Oracle products.

Oracle said Thursday it plans to release 27 security fixes for its business software, including Oracle Database, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite, Oracle Enterprise Manager Grid Control, Oracle PeopleSoft Enterprise PeopleTools, and Oracle PeopleSoft Enterprise Human Capital Management.

Oracle said there were no security fixes forthcoming for its JD Edwards products.

None of the Oracle Database vulnerabilities can be exploited remotely without authentication, meaning an attacker would have to be in possession of a valid user name and password to take advantage of the database flaws.

IT managers may be more concerned about the vulnerabilities in other products. Three of the seven fixes specific to the Oracle E-Business Suite may be exploited remotely, without authentication. One of the four fixes for Oracle's PeopleSoft products also may be exploited remotely, without authentication.

Oracle makes a habit of releasing security patches every three months. Its scheduled January patch contains significantly fewer fixes than in previous quarters. In October, the company released 51 fixes; in July, it released 45.

Security researchers like those with the SANS Institute have noted that attackers are looking for holes in corporate applications more than they had in the past. At the very least, security researchers are finding more such holes: Milw0rm.com, a site that catalogs published code exploits, posted 21 Oracle-related exploits in 2007, five in 2006, and three in 2005.

Author: Thomas Claburn @ www.informationweek.com


Read more ...

10.1.08

Oracle XML DB generates power for electrical agency

The Northern California Power Agency (NCPA) is using Oracle Database 11g and Oracle XML DB to help area utilities deal with a major technology overhaul and integrate power supplies more efficiently.

Headquartered in Roseville, Calif., NCPA is a public agency that for 40 years has assisted Californian power utilities in the purchase, generation, transmission, pooling and conservation of electrical energy and capacity. And since plans for a major technology upgrade known as the California Independent Systems Operator's energy market redesign and technology update (MRTU) effort began taking shape, NCPA has become a primary supplier of power scheduling services for public agencies.

MRTU is a comprehensive program designed to enhance the reliability of the Californian power grid by keeping the state compatible with market designs in use throughout North America and replacing legacy technology with modern computer systems.

The program, which has been under development since 2000, with final implementation planned for late March, will require utilities to process extremely large and complicated data files, known as power settlement files, which allow the various utilities to pool and share power supplies more effectively.

Working with Oracle, NCPA created a research application that runs on top of Database 11g and makes use of XML DB -- a feature of Database 11g that provides XML storage and retrieval capabilities -- to give utilities an easier way to search and process the power settlement files. Through an open source license, NCPA will offer its Cal-ISO settlement database application free of charge to any California electric utility, marketer, generator or vendor.

The idea is to save energy market stakeholders time and -- more importantly -- money, and the NCPA says those savings will trickle down to anyone who pays a power bill.

"As part of this redesign, the databases that we were going to have were going to be extremely large [and] they were moving to an XML infrastructure on the database," said Mark Myers, NCPA's manager of IT. "So we started looking at XML DB as a way to solve our database [issues]."

According to Myers, most of California's power agencies opted to deal with the new power settlement files by building a traditional database, bringing in all of the new data, parsing it and building tables.

NCPA, however, opted to use XML DB to build an application that would allow the agency to download settlement files data directly into the specific applications that needed it. But there were some challenges along the way, particularly when it came to convincing MRTU authorities at the ISO to stick with certain XML standards.

"We had to insist that they kept the W3C standards," Myers said. "It took a couple of years to make sure that all of those standards were kept. [But] when the standards were kept, things worked great."

Myers said another big challenge was ensuring that other business users within the energy marketplace stick with the same standards as well.

"When you're in a market situation and getting that excess data from another person, if they decide to change that data, then your whole solution could be in jeopardy," Myers said. "That's why we gave the solution away, to counteract that negative. We've had upwards of 30 different companies request the application now."

For business users, the new application has been a godsend from a data-mining point of view because they're now able to search entire databases-worth of settlement information much more quickly and thoroughly than in the past, according to Bob Caracristi, manager of power settlements at NCPA.

"The performance is good, and yet I have so much more data available for me to use," he said. "The ability to look at the whole database gives us more critical insight."

The NCPA says that Oracle was instrumental in helping it come up with the XML DB-based answer to the power settlement issue.

"We've engaged with a number of customers over the years with this kind of solution," said Mark Drake, Oracle's product manager for XML DB. "It's been a very successful relationship with the NCPA."

Author: Mark Brunelli @ searchoracle.com


Read more ...

9.1.08

Oracle Announces New Integration Between Oracle’s PeopleSoft Enterprise 9 and Oracle Customer Hub

Oracle Fusion Middleware Integration Delivers Value Through Synchronized Master Data Management and CRM Data for Better Customer Experience.

Oracle today announced out-of-the-box Oracle(r) Fusion Middleware based integration between Oracle's PeopleSoft Enterprise Customer Relationship Management (CRM) 9 and Oracle Customer Hub. PeopleSoft Enterprise CRM customers can now take direct advantage of the state-of-the-art MDM capabilities for data quality management, data enrichment, and customer mastering capabilities, enabling an even better customer experience through deep customer data integration that keeps incremental changes to customer records within PeopleSoft Enterprise CRM synchronized with the Oracle Customer Hub in real-time.

The need to better understand customer data and keep it up-to-date throughout the enterprise is a constant challenge, often leading to expensive and time-consuming implementations. With the new integration between PeopleSoft Enterprise CRM and Oracle Customer Hub, users can easily cleanse and remove customer information duplications across systems and realize effective customer information consolidation, data quality management, governance and sharing of data across the enterprise. The integration helps eliminate costly undertakings and deliver all the benefits of customer insight, reduced data management & marketing costs, and effective compliance with regulations.

Key functionality for the new integration includes:

* Real-time, bi-directional sync of customer data between PeopleSoft Enterprise CRM and Oracle Customer Hub through Oracle BPEL Process Manager.
* Enhanced "fuzzy" search capabilities in PeopleSoft Enterprise CRM customer search screens using data quality management (DQM) configurable match rules.
* Duplicate prevention in real-time from PeopleSoft Enterprise CRM customer entry screens.
* Identification of duplicate customers within PeopleSoft Enterprise CRM and merge of duplicate customers using the Oracle Customer Hub Data Steward. Customer records are merged in the Oracle Customer Hub and PeopleSoft Enterprise CRM.
* Real-time and batch customer data enrichment using out-of-the-box connection services to Dun & Bradstreet (D&B).

The PeopleSoft Enterprise CRM integration to Oracle Customer Hub is standards-based and provides the framework for customers to integrate other third-party customer data hubs and data quality tools that they may already have in place. Implementing Oracle Customer Hub as part of PeopleSoft Enterprise CRM is one of the first steps to start benefiting from Oracle Fusion architecture today.

"PeopleSoft Enterprise CRM customers need the ability to cost-effectively determine a single version of customer data across the enterprise," said Oracle Vice President of MDM Strategy Pascal Laik. "The integration helps the enterprise clear a major hurdle for data management and experience even further value and insight into their customer data."

Source: www.crm2day.com


Read more ...