A New Fix for WebLogic Server Patch
Patching does not necessarily solve security issues, as the hackers are again able to take advantage of the vulnerability. Cyber attackers have found a new way around the recently launched patch for Oracle WebLogic Server flaw.
The patch contained 254 new security fixes for the Oracle WebLogic Server flaw that affected few versions of the Oracle WebLogic Server. However, a Chinese researcher discovered a way that allows the WebLogic vulnerability to be exploited again enabling hackers to gain control of a vulnerable server. Considering that the proof of concept was published in the past, the patch is rather easy for trained hackers to figure out because of the shared information on social media.
Currently, there is no confirmation of servers being attacked with this vulnerability, but Oracle WebLogic Server has been known to be targeted by malicious hackers. In January, it was reported that hackers were leveraging a web application server flaw that Oracle asserted to have patched.
When vulnerabilities are revealed, organizations often hustle to offer a fix before the flaw can be exploited in the open. This newly identified faulty patch advises that hurrying up to release an update does not help much in mending the problem. The reports should not stop users from installing the recent patch update because attackers continue to scrutinize the internet for exposed servers.
By John Kamin, EVP and CIO, Old National Bancorp
By Gregg T. Martin, VP & CIO, Arnot Health
By Dave Doyle, CIO & SVP, IT, Regal Entertainment Group
By Sergey Cherkasov, CIO, PhosAgro
By Adrian Mebane, VP-Global Ethics & Compliance, The Hershey...
By Mike Fitton, Wireless Business Unit Director, Altera
By Jim Kaskade, VP and GM, Big Data & Analytics, CSC
By Thomas Musgrave, EVP & CIO, AmeriCold Logistics
By Vin Sharma, Director, Strategic Planning & Marketing, Big...
By Federico Flórez, Chief Information & Innovation Officer,...
By Barbara Adams, VP, Innovative Technology Solutions, Texas...
By John Mason, CIO, Bottomline Technologies
By Jamshid Khazenie, CTO, USA Today Network / Gannett
By Miguel Gamino, CIO & Executive Director-Department of...
By Bill Schimikowski, VP, Customer Experience, Fidelity...
By Tom Bressie, Vice President, Oracle Cloud
By John Landwehr, Public Sector CTO, Adobe
By Aaron Gette, CIO, The Bay Club Company
By Denise Zabawski, CIO, Nationwide Children's Hospital
By Amit Bahree, Executive, Global Technology and Innovation,...