Slashdot Mirror


Oracle Patch Day Becoming Irrelevant

mocirac wak writes "Oracle's scheduled quarterly patch day is becoming more and more irrelevant. Oracle critical patches announced in the April 2006 CPU are still not available for download and the ETA is now set for May 15. The whole idea of a patch day was to let DBAs get prepared for testing and deployment. What's the use of having a patch day when there are no patches to download?" From the article: "... Oracle's explanation that patch testing is not yet done points to serious shortcomings and an absence of a good patch development process. 'For such a big organization with a lot of financial resources, they should be ready to handle this without problems. But they are amateurs on everything security related,' Cerrudo said. 'They spend a lot of time creating these patches. Then, patch day comes around and the patches aren't available. Then, when the patches are finally released, it's normal to find that they are incomplete and fail to address the actual vulnerability,' he added."

1 of 76 comments (clear)

  1. limited set unavailable? by Fro+Ingwe · · Score: 5, Insightful

    I'm an Oracle DBA by trade and was able to patch my test systems running Oracle 9iR2 within days of the scheduled release date.

    The article makes it sound like the target date was missed entirely, and while I know there are delays for some releases, others were made available as planned.

    Why do I get the feeling that most of the complaining here is by people who don't actually use the product?