OS and DB Security patches and updates

Dear Experts,
We are going through SOX audits. Auditor is asking me about applied latest OS and Oracle patches to secure SAP systems from threats and attacks.
I told them that we are running on Solaris 9 with Oracle 9.2.0.5
and our severs are behind CHECKPOINT Firewall, and also we have never faced any security breaches and threats and also not facing any performance and efficiency problems in our system.
However, they still persist me about critical security patches for Solaris and Oracle.
Please tell me should I go for applying security patches of Solaris or Oracle if any. I am very worried about possible problems after applying of those security patches.
Please guide me about this issue and tell me about proven and trusted security patches for Solaris 9 and Oracle 9.2.0.5
Best Regards
Waqas Ahmad

> I told them that we are running on Solaris 9 with Oracle 9.2.0.5
First I would like to tell you that your current Oracle version is out of extended support (see SAP on Oracle and the notes the first chapter points to). To get actual (security) patches I would highly recommend upgrading to 10.2.0.4.
> However, they still persist me about critical security patches for Solaris and Oracle.
They do that because most of the "attacks" to server come from internal users, not from external.
> Please guide me about this issue and tell me about proven and trusted security patches for Solaris 9 and Oracle 9.2.0.5
For the operating system I would use pca (Patch Check Advanced) - a free too to download and install patches - works like charm (http://www.par.univie.ac.at/solaris/pca/). It can be configured to only download and install security relevant patches.
For Oracle you should install the latest patchset (for 9.2 it's 9.2.0.8 and all the necessary interim patches) and the critical patch updates. However, those CPUs may conflict with necessary other patches so you can either use CPU or the necessary interim patches.
Check note 938986 - Oracle Database 9.2: Patches for 9.2.0
Markus

Similar Messages

  • Slow macbook pro since the airport security patch and last OS update about a week ago..

    Hi, my Macbook Pro has slowed down to a crawl on the internet since the airport security patch and OS update about 1 week ago.  I am using Firefox 3.6.17 and have tried all versions up to date (but 3.6.17 is the best).  Same issues with Safari too.  I am using an Airport wireless modem also so should not be any issues with compliance.  Local programs seem to run OK... but the internet is slow enough to grow a beard... Do they have a patch for this issue.  It only started after the updates.  Was blazing fast until that.

    How large is your hard drive and how much hard drive space do you have left?
    Disconnect all peripherals from your computer. Boot from your install disc & run Repair Disk from the utility menu. To use the Install Mac OS X disc, insert the disc, and restart your computer while holding down the C key as it starts up.
    Select your language.
    Once on the desktop, select Utility in the menu bar.
    Select Disk Utility.
    Select the disk or volume in the list of disks and volumes, and then click First Aid.
    Click Repair Disk.
    Restart your computer when done.
    Repair permissions after you reach the desktop-http://docs.info.apple.com/article.html?artnum=25751 and restart your computer.

  • HT201269 When I try to setup my new iPad air, I go through all the steps for the iCloud sign-in and choosing security questions and what not. But after I hit the agree to the terms and conditions... It says Apple ID could not be created because of a serve

    When I try to setup my new iPad air, I go through all the steps for the iCloud sign-in and choosing security questions and what not. But after I hit the agree to the terms and conditions... It says Apple ID could not be created because of a server error. Have no clue what to do... I've restarted the iPad and get the same message. But my internet works just fine.

    1. Turn router off for 30 seconds and on again
    2. Settings>General>Reset>Reset Network Settings

  • TS1398 I only want my secured network wifi but keeps searching for others.  Tried turning on an off wifi and on and off secured networks and ignore other networks, but keep coming back. Any suggestions.

    I only want my secured network wifi but keeps searching for others.  Tried turning on an off wifi and on and off secured networks and ignore other networks, but keep coming back. Any suggestions.

    That's not the way wifi works.
    You may see the other networks but you are not connected to them in any way.

  • Install IE10 and required security patches with WSUS with only 1 or 2 reboots

    We are planning to deploy IE 10 with WSUS.  Currently, it takes 1 reboot to apply IE 10 and 2 subsequent reboots to apply all the identified security patches for IE 10 via WSUS.  We are under close scrutiny to limit the number of times that computers
    must be rebooted to apply patches so that we don't impede our business function.
    Is there anyway to deploy IE 10 and all required IE 10 security patches with WSUS with only a single or 2 reboots?  As I understand WSUS already "packages" or "layers" patches in a manner to limit the number of reboots and that
    various patches must be installed only after pre-requisite patches are identified as installed.
    We are rolling out to a couple thousand machines and want to make the business impact as little as possible.
    Any help would be appreciated.

    and 2 subsequent reboots to apply all the identified security patches for IE 10 via WSUS.
    I find this unusual. Exactly how did you determine this to be the case. Which updates are you actually deploying to an IE10 environment?
    My investigation identifies that the only two updates are applicable to an IE10 (on Windows 7) environment. They are MS14-011 (KB290920), released Feb 2014,  and MS14-056 (KB2987107), released Oct 2014. Since these two updates *CAN* be installed
    concurrently, at worst these two updates installed concurrently would only trigger one reboot -- assuming they trigger a reboot at all.
    Lawrence Garvin, M.S., MCSA, MCITP:EA, MCDBA
    SolarWinds Head Geek
    Microsoft MVP - Software Packaging, Deployment & Servicing (2005-2014)
    My MVP Profile: http://mvp.microsoft.com/en-us/mvp/Lawrence%20R%20Garvin-32101
    http://www.solarwinds.com/gotmicrosoft
    The views expressed on this post are mine and do not necessarily reflect the views of SolarWinds.

  • I think my other account is hacked and the hacker changed the password and the security questions and i can't retrieve it , so does anyone know how to have a live (online) conversation with a senior or an apple employee responsible for such problems ?!

    Please help me because it's not the first time the account has been hacked, every time i found out that it was hacked i changed the password, but this time it is not easy because he changed the alternative email-adress and the security questions.

    Call the Apple support phone number for your country:
    http://support.apple.com/kb/HE57
    and the 1st tier agent should be able to assist you or transfer your call to the Account Security team.
    Regards.

  • 1Z0-238 and 11i Install, patch and maintain.....

    hi,
    I took the "11i Install, patch and maintain Oracle Applicaiton" course from oracle university about couple of years ago and now we are already on release 12.0.6. I want to attempt 1Z0-238 which is actually a R12 certificaftion exam. Question is; Can i attemp 1Z0-238 a release 12 exam with a course taken from previous release.
    I dont want to be in situation where oracle will say either take the R12 course or re attemp an 11i exam..... :(
    Your valueable comments are very much appriciated.
    thansk and regards,

    Anyone know if there are any plans in the works for an Oracle Press book for the 1Z0-233 exam?
    Also, has anyone read:
    Installing, Upgrading and Maintaining Oracle E-Business Suite Applications Release 11.5.10+ (Or, Teaching an Old Dog New Tricks - Release 11i Care and Feeding (Paperback)
    by Barbara Matthews (Author), John Stouffer (Author), Karen Brownfield (Author)
    http://www.amazon.co.uk/Installing-Upgrading-Maintaining-E-Business-Applications/dp/0615141226/ref=pd_bbs_3/203-4846580-6320739?ie=UTF8&s=books&qid=1188203474&sr=8-3
    And is it any good? No reviews yet on amazon, or elsewhere that I've found.
    Thanks for the info,
    Tony

  • SCCM 2012 R2 changing date and time for patching software update groups

    I recieve this error when changing date and time for software update group. worked fine yesterday before patches to the server were applied last night. we removed patches but still get error below. Any help would be great.
    ConfigMgr Error Object:
    instance of SMS_ExtendedStatus
    Description = "Property array AssignedCIs exceeded the max allowed";
    ErrorCode = 1078462259;
    File = "e:\\nts_sccm_release\\sms\\siteserver\\sdk_provider\\smsprov\\sspupdatesassignment.cpp";
    Line = 94;
    Operation = "PutInstance";
    ParameterInfo = "";
    ProviderName = "ExtnProv";
    StatusCode = 2147749889;
    Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlQueryException
    The SMS Provider reported an error.
    Stack Trace:
    at Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlResultObject.Put(ReportProgress progressReport)
    at Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlResultObject.Put()
    at Microsoft.ConfigurationManagement.AdminConsole.SmsDialogData.Put(IResultObject resultObject, List`1 resultObjectsPut, Boolean retainLock)
    at Microsoft.ConfigurationManagement.AdminConsole.SmsDialogData.Put(Boolean retainLock)
    at Microsoft.ConfigurationManagement.AdminConsole.DialogFramework.Forms.SmsPropertySheet.Put(ActionTrigger trigger)
    System.Management.ManagementException
    Generic failure
    Stack Trace:
    at Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlResultObject.Put(ReportProgress progressReport)
    at Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlResultObject.Put()
    at Microsoft.ConfigurationManagement.AdminConsole.SmsDialogData.Put(IResultObject resultObject, List`1 resultObjectsPut, Boolean retainLock)
    at Microsoft.ConfigurationManagement.AdminConsole.SmsDialogData.Put(Boolean retainLock)
    at Microsoft.ConfigurationManagement.AdminConsole.DialogFramework.Forms.SmsPropertySheet.Put(ActionTrigger trigger

    no it is the final version... is working today after cleaning up database... is working now...thanks
    Hello Robert,
    would you please give some more informations, as I have the same issue and don't get what you mean bye "cleaning up databases".
    Regards ooGDoo
    ooGDoo

  • Security Patches and features

    Knowing that the XE is currently beta, is Oracle going to make patches available for XE as it is doing for the other RDBMS products?
    Is there any plans for having a GUI version of SQL*PLUS included with XE?
    Is there a supported way to move the XE executables and DB from default directory structure? We have a standard directory structure that has been certified for our work stations. The default direct structure conflicts with this standard. If there is not a supported way, then I'll see if I can get a wavier to maintain the directory structure as is.
    I am currently evaluating XE for use in replacing an Oracle 8.1.5 database that is used as a standalone system when the main systems are unavailable (10.1.0.3.0 and 10.2.0.1.0). So far, XE has met or exceeded my expectations, and look forward to the production version.
    Thanks.
    Don Jones

    Is there any plans for having a GUI version of
    SQL*PLUS included with XE?
    Almost certainly not. sqlplusw.exe which is a windows only tool is being withdrawn from all versions of the database.
    Oracle SQL Developer is probably the way to go if you want GUI

  • I lost my menu bar and AVG Security Toolbar and immediately switched back to the previous version of Firefox.

    After installing Firefox 4 beta and restarting I no longer had my menu bar (File Edit...) nor my AVG Safe Search Security Toolbars. As a result, I immediately reinstalled the previous version of Firefox which I had installed just a few minutes previously. In the future, I will make sure I have the install/exe for this version so that I can be insured of having a version that functions properly. Until then, and in the future, I WILL NOT be beta testing any versions of Firefox/Thunderbird. I just don't feel comfortable risking it as I am computer illiterate, it's not worth the danger...

    In addition I lost my "Home" button, including with the version I now run (3.6?) and had to create a folder for the location on the menu toolbar.

  • Not Booting after recent Security Patch/Java update

    My wife has experienced what many have experienced with the recent update.
    MacBook not booting after update (i.e. - "I have no name!")
    I have tried everything posted on this topic since 2/13/09, but without any success. Does anyone have the fix for this yet?
    Things I have tried:
    * I can boot in safe mode (holding "Shift" while restarting)
    * I cannot boot from an install disk(s) (holding C while restarting) - I have both a black one from purchase, and two gray ones with purchase from MiniMac
    * Booting with verbose - gets stuck at same place as everyone else
    Operating in safe mode:
    * I can run DU and "repair" drive
    * I can see and access the CD/DVD
    * I cannot see drive in target drive mode (doesn't ever connect the 2 systems)
    * I downloaded the update files from apple and reinstalled them individually (via USB ext Drive) with a reboot in between
    * I attempted to update & archive, but I cannot run install CD from any systems disks (see above)
    Has anyone figured out how to fix this yet?

    Same problem than the other guy who is not mentioning the update in the title.
    Powerbook 1.67.
    System log said "No user defined computer name" and "using blah blah name" or so.
    Mac Os X report (for apple) says:
    Unresolved kernel trap(cpu 0): 0x300 - Data access DAR=0x000000003900FF1C PC=0x00000000008FC020
    Latest crash info for cpu 0:
    Exception state (sv=0x4299D280)
    PC=0x008FC020; MSR=0x00009030; DAR=0x3900FF1C; DSISR=0x40000000; LR=0x008FE348; R1=0x2C47B9F0; XCP=0x0000000C (0x300 - Data access)
    Backtrace:
    0x008FE348 0x008E0014 0x002E9A80 0x002EB94C 0x0008C248 0x00029234
    0x000233F8 0x000ABEAC 0xFF9BA29B
    Kernel loadable modules in backtrace (with dependencies):
    com.apple.ATIRadeon9700(4.1.8)@0x8d8000
    dependency: com.apple.iokit.IOPCIFamily(1.7)@0x48d000
    dependency: com.apple.iokit.IOGraphicsFamily(1.4.2)@0x85a000
    dependency: com.apple.iokit.IONDRVSupport(1.4.2)@0x87e000
    Proceeding back via exception chain:
    Exception state (sv=0x4299D280)
    previously dumped as "Latest" state. skipping...
    Exception state (sv=0x43D0D000)
    PC=0x9000AF48; MSR=0x0200F030; DAR=0x0ECA77FE; DSISR=0x42000000; LR=0x9000AE9C; R1=0xBFFFD6C0; XCP=0x00000030 (0xC00 - System call)
    Kernel version:
    Darwin Kernel Version 8.11.0: Wed Oct 10 18:26:00 PDT 2007; root:xnu-792.24.17~1/RELEASE_PPC
    panic(cpu 0 caller 0xFFFF0003): 0x300 - Data access
    Latest stack backtrace for cpu 0:
    Backtrace:
    0x000954F8 0x00095A10 0x00026898 0x000A8204 0x000ABB80
    Proceeding back via exception chain:
    Exception state (sv=0x4299D280)
    PC=0x008FC020; MSR=0x00009030; DAR=0x3900FF1C; DSISR=0x40000000; LR=0x008FE348; R1=0x2C47B9F0; XCP=0x0000000C (0x300 - Data access)
    Backtrace:
    0x008FE348 0x008E0014 0x002E9A80 0x002EB94C 0x0008C248 0x00029234
    0x000233F8 0x000ABEAC 0xFF9BA29B
    Kernel loadable modules in backtrace (with dependencies):
    com.apple.ATIRadeon9700(4.1.8)@0x8d8000
    dependency: com.apple.iokit.IOPCIFamily(1.7)@0x48d000
    dependency: com.apple.iokit.IOGraphicsFamily(1.4.2)@0x85a000
    dependency: com.apple.iokit.IONDRVSupport(1.4.2)@0x87e000
    Exception state (sv=0x43D0D000)
    PC=0x9000AF48; MSR=0x0200F030; DAR=0x0ECA77FE; DSISR=0x42000000; LR=0x9000AE9C; R1=0xBFFFD6C0; XCP=0x00000030 (0xC00 - System call)
    Kernel version:
    Darwin Kernel Version 8.11.0: Wed Oct 10 18:26:00 PDT 2007; root:xnu-792.24.17~1/RELEASE_PPC

  • HT2534 I have my Apple ID but there is a pop up menu that tells me to review my info.But   when i clicked Review it says that i have to put a card number and a security code,and the expiration date pls help me..

    When I started to install Apps. on my iPad there,a message tells me that I have to review my Info.After clicking review there are only 3 choices:VISA,MasterCard and Amex.But we don't have credit card.What should I do?

    You cannot use that ID without a credit card. You did not create your account correctly. There is very specific way in which you must create your account if you do not want to use a credit card. If you don't have a credit card, you will have to start all over again.
    1. You will have to sign out of that ID before you can create a new one. Settings>iTunes & App Store>Apple ID>Sign out.
    2. You cannot use the email address that you used for the first ID that you created. You will need to use another email address now
    3. You have to download a free app in order to start the new Apple ID process.
    Read this before proceeding.
    http://support.apple.com/kb/HT2534

  • I am trying to download aps and forgot security question and connot download

    How do I change my security questions if I forgot them

    Click here for information. If you can't get the answers emailed to you for some reason(the email may take a few hours to arrive), contact the iTunes Store staff via the link in that article.
    (87737)

  • Office 365(O365) and Windows Security Pop-Up When opening outlook

    This post is being transfered from the office 365 team because they created a brand new profile and i still get the same problem when connecting to their newly created one.
    Any help you can provide would be much appreciated.
    I really would like email running. Thanks very much !!!
    Hi Everyone I have seen some threads on this topic and i have tried to follow all of their instructions and it hasn't solved my problem.
    So this problem started happening 2 days ago.
    Each time i open outlook I get prompted for Login Credentials. It has never happened before
    I have tested it using this tool https://testconnectivity.microsoft.com and it works fine
    I have removed my security credentials on the PC it hasn't solved it
    I have a number of tablets and they are working fine
    I have built new Outlook profiles
    I have tried it in safe mode
    In the Security settings for the Outlook Mail profile is set to Not Prompt for Security Credentials
    The Login Security Mode is set to "Negotiate Authentication"
    I have tried it with both Encryption and without
    I'm able to login to Email online and send and recieve emails that way.
    I have another user on Windows 8.1 and the problem started happening at the same time as me. I'm on Windows 7 Office 2010 Plus Proffessiona
    I believe the other user is on a newer version of outlook than me.
    I have spent all night trying different things and nothing has worked
    I could really use your help.
    Any help would be much appreciated i'm quite frusted not being able to send mail from outlook
    Hi Alan,
    I am sorry for the issue you are experiencing right now.
    On Tuesday, August 5, 2013 at approximately 12:45 PM UTC, we receive a report that some of the users were unable to authenticate to the Exchange Online service when using the Outlook client. However, the issue has been restored.
    Since you are still having the issue, please follow the steps below to do the confirmation.
    1. Please make sure that all Outlook security patches and updates are installed on the affected computer. To check for the latest Outlook updates, please click on the link below.
    2. To make sure whether the issue is related to the Outlook client or the service, please try configuring the test account I send you through private message on the affected computer to check whether the issue exists. To check the private message, please follow
    the steps.
    a. Please go to Your details section on the right side of the community site.
    b. Click Private messages.
    c. Click the subject title of the responses to read the message.
    Please provide feedback, then we can move forward to check where exactly to look into the issue.
    At last, I would like to confirm whether your organization only have Exchange Online or have hybrid environment.
    Thanks,
    Yang Yu
    I noticed something a bit strange that SMTP is automatically put in front of the mailbox name.. i haven't seen that before
    Went to windows update and there is nothing to install
    it's interesting you say the 5th because that is exactly the last day that outlook successfully synced.. it hasn't worked since.. This is happening on 2 seperate computers and stopped working at the exact same time.
    Hi Alan,
    Thanks for the update.
    Based on the currently situation, I understand when configuring the test account provided by Yang Yu the issue persists. And you have a number of tablets and they are working fine. Thus the issue could be related to the certain Outlook client on this certain
    computer.
    Since we focus on Office 365 issues in this forum, I'm so sorry that I’m not able to provide the detailed instructions.
    To provide you with a better service, and sort out this issue more effectively, I suggest you post this issue in the following Outlook forum. The engineers there will help you get the issue fixed in a timelier manner.
    Outlook forum:
    At the same time, I will also continue doing some further tests and research. Thanks for your understanding and great efforts.
    Any community members with related experience on this issue who could share it here are also appreciated.
    Regards,
    Xinyu

    Hi Alan,
    According to your description, the Outlook settings seems to be correct in your local machine. And some solutions have been tried to solve this issue:
    Create a new Outlook profile, start Outlook in safe mode, clean credentials cache in computer ect.
    But the issue persists. Please consider to configure your account on a computer which is working file with your colleague's Office 365 account to check whether the issue continues. If the issue only happens to your account, please access the mailbox in Webmail
    and change the password to have a try.
    Regards,
    Winnie Liang
    TechNet Community Support

  • Patches and SunSolve

    I have already mentioned in a couple of previous postings that, I am trying to install
    studio 11 on a system on which Forte Developer 7 is already installed.
    My question is, if I install studio 11 , is it still necessary for me to run
    "version libC*" command under /usr/lib directory in order to check whether latest
    patches are installed or not ?
    I am under the impression that : I need not , as I am installing Sun studio 11 which is
    the latest studio available. Can any body please confirm this ?
    In case I am supposed to check whether latest patches are installed or not, the document says
    I need to register myself with SunSolve. When I tried to register myself with SunSolve it asked me to
    enter Service Plan. But I am not sure which Service plan I should enter . Can any body help me ?
    Thanks,
    Ramesh.

    When you install Sun Studio 11, you have the option of also installing the required Solaris patches. You should accept that option, because Studio 11 will not run properly if the requried patches are not present. The patch installer will update a file only if it is a newer version than the one already on the system.
    Some of the patches are for system libraries like the C++ runtime libraries. There is only one copy of each of these libraries on the system, installed in /usr/lib, and shared by all compilers and programs that need them. Old compilers can use new versions of these libraries, so it is always safe to install the newest patch.
    Sun's upport model for free Solaris and free compilers is that most patches require a support contract. The current exceptions are security patches, patches for Sun Studio, and Solaris patches required by Sun Studio.
    If you go to the Sun Studio patch page
    http://developers.sun.com/prodtech/cc/downloads/patches/index.jsp
    you should be able to follow the links to the Sun Studio and required Solaris patches, and download them directly.

Maybe you are looking for

  • Purchase order status report

    hi, can any one give an idea regarding to generate a report for purchase order status this report gives a list of purchase orders that are against given sales order item this report also gives the delayed status of purchase orders. 1. user will give

  • Apex 4 , problem with collection executions

    Hi , I am having the following problem with the execution of one collection : Reference thread : Re: APEX 4 , executing a remote procedure and populating data using collection DBNAME ---> list item which I build from the DB links which I built ( as d

  • Do i have to do something configuration in weblogic 6.1 to put a javabean?

    Hi, I'm trying to do a simple example about a simple javabean....but it...is giving to my some errors....my question is: Do i have to do something configuration in weblogic 6.1 to put a simple javabean?... i have created a web application called mywe

  • Apple TV don't display my Music?

    Hi, Any tips on how to show (and play!) My Library on the Apple TV ? Cheers, Fabien

  • Network Downtime measuring with CW LMS 3.1

    We have a network of about 750 Devices. We have implemented LMS 3.1 as a primary NMS in our NW. Now we want to measure total downtime in a month through CW LMS. How to do that ?