• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCybersecurity

Oracle’s security conundrum

Barb Darrow
By
Barb Darrow
Barb Darrow
Down Arrow Button Icon
Barb Darrow
By
Barb Darrow
Barb Darrow
Down Arrow Button Icon
October 30, 2015, 10:24 AM ET
Oracle

At Oracle OpenWorld this week, company execs spent a good chunk of their stage time talking about security. Executive chairman Larry Ellison, for example, extolled the security virtues of Oracle’ s (ORCL) new M7 microprocessor, which he said bakes software security features from the latest release of its Oracle database right into the silicon.

Ellison mentioned several times that security problems arise because customers either do not enable the software’s security features or intentionally switch them off. That ability, however, will not be an option with the M7 since “we turn it on and you can’t turn it off,” he told show attendees.

The remarks come just weeks after Oracle,(ORCL) which had no comment on this story, released an eyebrow-raising set of 154 security fixes in a Critical Patch Update covering many of its key products. It is particularly important with this update that customers implement right away because the update includes “a number of fixes for very severe vulnerabilities,” according to a blog post about the update.

An IT consultant who works with federal agencies on Oracle implementations said this update was nothing short of a scandal because Oracle’s “entire product fleet was affected: pretty much every database, middleware web and app server. Everything,” said the specialist who requested anonymity because he works with the company’s customers.

Some of the vulnerabilities could give ​uncredentialed​ hackers the ability to remotely execute operations. In theory, that means a random-but-code-savvy Joe Shmoe with access to the Internet could run database queries on your business system, or even change data values. “That’s bad,” the consultant said.

The gnarly issue of patching software is not unique to Oracle, but because the company has made a point of calling its own products “unbreakable,” it pretty much put a bullseye on its own back. Hackers love a good challenge after all.

Gartner (IT)research director Lawrence Pingree said technology providers have to issue patches promptly to keep customers safer from data breaches. “It is quite well known in the security industry that one of the best ways to avoid a data breach is to simply make sure you are deploying patches quickly,” he said via email.

But, although patch updates are standard operating procedure, Oracle is in the spotlight because so many customers use the company’s databases and financial applications to run their businesses, which leaves little room for tolerance or error. We’re not talking about Candy Crush here.

It also doesn’t help that many corporate customers have come to resent Oracle’s technical support and maintenance fees. If you’re paying 22% of your license cost to stay supported, you have high expectations when it comes to security.

Meanwhile, it probably did not help Oracle’s relationships when in August Mary Ann Davidson, Oracle’s chief security officer, took to her blog to chastise corporate customers for performing their own security tests on company software. In the post she even noted that such tests could violate their licensing agreements. The blog was quickly pulled down and Oracle backed away from her claims.

Never ones to let a good crisis go to waste, tech companies are using these security woes to push customers to move to what they’re painting as cloud Nirvana. As Oracle CEO Mark Hurd stressed during his keynote, most enterprise applications are now 20 years old—that’s a lot of legacy code that needs to be maintained, bolstered, and updated. Oracle’s new pitch is for customers to move to the cloud—Oracle’s cloud of course. “We are fully patched, fully secured, fully encrypted,” Hurd noted.

For more on data security from industry leaders including Arlette Hart, the chief information security officer of the FBI, be sure to check out the Structure Conference next month.

 

Follow Barb Darrow on Twitter at @gigabarb. Read her Fortune coverage at fortune.com/barb-darrow or subscribe via her RSS feed.

And please subscribe to Data Sheet, Fortune’s daily newsletter on the business of technology.

 

About the Author
Barb Darrow
By Barb Darrow
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.


Most Popular

placeholder alt text
Future of Work
Ford CEO has 5,000 open mechanic jobs with up to 6-figure salaries from the shortage of manually skilled workers: 'We are in trouble in our country'
By Marco Quiroz-GutierrezJanuary 31, 2026
1 day ago
placeholder alt text
Economy
'I just don't have a good feeling about this': Top economist Claudia Sahm says the economy quietly shifted and everyone's now looking at the wrong alarm
By Eleanor PringleJanuary 31, 2026
2 days ago
placeholder alt text
Success
Ryan Serhant starts work at 4:30 a.m.—he says most people don’t achieve their dreams because ‘what they really want is just to be lazy’
By Preston ForeJanuary 31, 2026
1 day ago
placeholder alt text
Big Tech
The Chan Zuckerberg Initiative cut 70 jobs as the Meta CEO’s philanthropy goes all in on mission to 'cure or prevent all disease'
By Sydney LakeFebruary 1, 2026
14 hours ago
placeholder alt text
Success
U.S. Olympic gold medalist went from $200,000-a-year sponsorship at 20 years old to $12-an-hour internship by 30
By Orianna Rosa RoyleFebruary 1, 2026
9 hours ago
placeholder alt text
Economy
Meet the first CEO of the IRS: A Jamie Dimon protégé facing a $5 trillion test this tax season
By Shawn TullyJanuary 31, 2026
2 days ago

Latest in Tech

Startups & Ventureautonomy
Waymo seeking about $16 billion near $110 billion valuation
By Edward Ludlow, Aaron Kirchfeld and BloombergFebruary 1, 2026
48 minutes ago
AIspace
SpaceX seeks FCC nod to build data center constellation in space
By Sana Pashankar, Loren Grush and BloombergFebruary 1, 2026
54 minutes ago
dewar
CommentaryLeadership
The AI adoption story is haunted by fear as today’s efficiency programs look like tomorrow’s job cuts. Leaders need to win workers’ trust
By Carolyn DewarFebruary 1, 2026
11 hours ago
trader
Investingbubble
‘We’re not in a bubble yet’ because only 3 out of 4 conditions are met, top economist says. Cue the OpenAI IPO
By Nick LichtenbergFebruary 1, 2026
12 hours ago
Big TechMark Zuckerberg
The Chan Zuckerberg Initiative cut 70 jobs as the Meta CEO’s philanthropy goes all in on mission to ‘cure or prevent all disease’
By Sydney LakeFebruary 1, 2026
14 hours ago
The founder and CEO of $1.25 billion AI identity verification platform Incode, Ricardo Amper
SuccessGen Z
CEO of $1.25 billion AI company says he hires Gen Z because they’re ‘less biased’ than older generations—too much knowledge is actually bad, he warns
By Emma BurleighFebruary 1, 2026
15 hours ago