DG0001: Vendor supported software is evaluated and patched against newly found vulnerabilities.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Unsupported software versions are not patched by vendors to address newly discovered security versions. An unpatched version is vulnerable to attack.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Upgrade to a supported Oracle version. Purchase an Oracle Extended Support Contract where required.

See http://www.oracle.com/technology/support/patches.htm for a definitive list of version patch sets for Oracle DBMS software.

See http://www.oracle.com/support/library/brochure/lifetime-support-technology.pdf for Oracle support policies and timelines.

See Also

http://iasecontent.disa.mil/stigs/zip/U_Oracle_Database_11g_V8R20_STIG.zip

Item Details

References: CAT|I, Rule-ID|SV-24339r2_rule, STIG-ID|DG0001-ORACLE11, Vuln-ID|V-5658

Plugin: Unix

Control ID: 33b9281b94ac400c56f4aa157b5a36bddf3f73a41aabe485100f1fe51219c934