May 2017 archive

Removing exposed HTTP Digest hash from user$ in Oracle 12.1

Background Oracle 12.1 has introduced a lot of new cool security features and improvements. We all agree with that. However, one of the most bizarre and security vulnerability things that Oracle did in this release was introducing HTTP Digest Authentication to allow XDB users to log in. The new EM Express Edition is one of the …

Continue reading

Where is Oracle Database 12.2.0.1 April 2017 PSU ?

Oracle 12.2 database is already available for more than 3 months. As expected, the first Patch Set for a given Release comes with a lot of bugs and we want as soon as possible a PSU to close all those gaps. However, I couldn't find the PSU for the 12.2 version on the quarterly April 2017 …

Continue reading