This month's update for Database Security Knowledgebase is now available. Knowledgebase version 5.12 includes new and updated checks for Oracle and Sybase ASE.
New Vulnerability and Configuration Check Highlights
Oracle
- SQL Injection in CDBView package
- Database Activity Monitoring - Monitor for attacks using sys.CDBView.create_cdbview SQL Injection.
- Risk: Auditing
- Relevant CVEs: N/A
Updated Checks
Sybase ASE
- Check for Sybase ASE 16.0 SP02 PL05 HF1
- Vulnerability Assessment - Latest patch not applied
- Risk: High
- Relevant CVEs:N/A
- Check for Sybase ASE 16.0 SP02 PL05 HF1
- Vulnerability Assessment - Patch not applied on time
- Risk: High
- Relevant CVEs:N/A
New Policies
- DISA-STIG SQL Server 2014 V1R3 - Audit (Built-In)
- DISA-STIG SQL Server 2012 V1R13 - Audit (Built-In)
Availability
- Available to allAppDetectivePRO and DbProtect customers with maintenance (subscription or perpetual) in good standing at no additional cost
- AppDetectivePRO customers can use the Updater within the product as well