Closed Thread
Results 1 to 10 of 10

Thread: Oracle has more Flaws than MS SQL?

  1. #1
    Jordan Guest

    Oracle has more Flaws than MS SQL?

    Study: Oracle database software has more flaws than SQL Server

    Microsoft is often unfairly slammed for security issues, says NGSS

    November 25, 2006 (Computerworld) -- Microsoft Corp may be taking the most heat among software vendors for security problems, but it's not always the one with the worst record.


    A comparison of vulnerabilities in Microsoft's SQL Server database with Oracle Corp.'s relational database management products by Next Generation Security Software Ltd. (NGSS) shows that the latter vendor's products to have far more vulnerabilities than do products from Microsoft.


    Between December 2000 and November 2006, external researchers discovered 233 vulnerabilities in Oracle's products compared with 59 in Microsoft's SQL Server technology, according to NGSS, which has worked for Microsoft in the past to make its software products more secure. The study looked at vulnerabilities that were reported and fixed in SQL Server 7, 2000 and 2005 and Oracle's database Versions 8, 9 and 10g.


    The results show that the reputation that Microsoft SQL Server had back in 2002 for relatively poor security is no longer deserved, said David Litchfield, founder of Surrey, England-based NGSS. And neither is the beating that Microsoft has gotten for security issues, he said.


    "I think it's time people got past this, especially security researchers," Litchfield said. "We should be about closing holes and improving a vendor's outlook on security and -- largely -- that battle has been won with Microsoft," he said. The results show that Microsoft's software development life-cycle processes appear to be working, he said.


    "There are other battles needing to be fought and won -- Oracle being one of them," Litchfield said.


    In an e-mailed comment, an Oracle spokeswoman said the number of reported vulnerabilities in a product alone is not a measure of the overall security of that software.


    "Products vary significantly in terms of richness of features and capabilities as well as number of versions and supported platforms," she said. "Measuring security is a very complex process, and customers must take a number of factors into consideration -- including use-case scenarios, default configurations as well as vulnerability remediation and disclosure policies and practices."




    Fully Story

  2. CODECALL Circuit advertisement

     
  3. #2
    Join Date
    Jul 2006
    Posts
    16,494
    Blog Entries
    75
    Rep Power
    143
    Personally, having used both products, I think you'd have to be touched in the head to voluntarily use Oracle. Their servers are a royal pain to configure.
    Programming is a branch of mathematics.
    My CodeCall Blog | My Personal Blog

  4. #3
    Jordan Guest
    I've never configured Oracle but I have watched it (all thirteen CDs). Once it is up and running I prefer Oracle though. I hate MS SQL servers, they irritate me bad.

  5. #4
    Lop's Avatar
    Lop
    Lop is offline Speaks fluent binary
    Join Date
    May 2006
    Posts
    1,178
    Rep Power
    30
    Would never have guessed that, Oracle seems like such a power house.

  6. #5
    Join Date
    Aug 2006
    Posts
    11,209
    Blog Entries
    6
    Rep Power
    101
    Hmm I cant believe that!! I thought that Oracle was the best :S

  7. #6
    Jordan Guest
    Quote Originally Posted by Tcm9669 View Post
    Hmm I cant believe that!! I thought that Oracle was the best :S

    Depends on who you talk to and what you need it for. I know guys that prefer MySQL, MS SQL and some of the other smaller ones.

  8. #7
    Join Date
    Jul 2006
    Posts
    16,494
    Blog Entries
    75
    Rep Power
    143
    Oracle's tools are written in Java: not a bad language, but very sluggish when interacting with the database.
    Programming is a branch of mathematics.
    My CodeCall Blog | My Personal Blog

  9. #8
    Lop's Avatar
    Lop
    Lop is offline Speaks fluent binary
    Join Date
    May 2006
    Posts
    1,178
    Rep Power
    30
    I like MySQL myself.

  10. #9
    Nightracer's Avatar
    Nightracer is offline Programmer
    Join Date
    Jun 2006
    Posts
    131
    Rep Power
    0
    Wow, that is hard to believe. I would think any MS product would automatically have more flaws.

  11. #10
    Join Date
    Aug 2006
    Posts
    11,209
    Blog Entries
    6
    Rep Power
    101
    Quote Originally Posted by Nightracer View Post
    Wow, that is hard to believe. I would think any MS product would automatically have more flaws.
    At least they did something right

Closed Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Oracle 10g (Help)
    By ahmed in forum Database & Database Programming
    Replies: 5
    Last Post: 04-26-2010, 06:16 AM
  2. Oracle
    By databox in forum Introductions
    Replies: 6
    Last Post: 01-17-2010, 05:33 AM
  3. Firefox Flaws still not cured in version 8
    By TkTech in forum The Lounge
    Replies: 9
    Last Post: 07-18-2008, 03:29 AM
  4. Firefox flaws?
    By mysticalone in forum Website Design
    Replies: 1
    Last Post: 01-16-2007, 09:29 PM
  5. Oracle?
    By Lop in forum C# Programming
    Replies: 7
    Last Post: 09-29-2006, 03:08 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts