Re: Oracle Data Redaction is Broken

  • From: Niall Litchfield <niall.litchfield@xxxxxxxxx>
  • To: David Litchfield <david@xxxxxxxxxxxxxxxxxxxx>
  • Date: Wed, 16 Jul 2014 15:13:37 +0100

Thanks David.
On 16 Jul 2014 13:47, <david@xxxxxxxxxxxxxxxxxxxx> wrote:

>   Hey all,
> As part of yesterday’s Critical Patch Update, Oracle fixed 3 security
> flaws in data redaction services – one a privilege escalation vulnerability
> and two redaction bypass methods. I reported these issues to Oracle in
> November last year and have documented them here:
> http://www.davidlitchfield.com/Oracle_Data_Redaction_is_Broken.pdf
> Cheers,
> David
>

Other related posts: