Security Market Segment LS
Friday, 22 November 2019 10:18

Oracle EBS flaws leave customers open to ERP system hacks

Oracle EBS flaws leave customers open to ERP system hacks Image by mohamed Hassan from Pixabay

Database vendor Oracle's E-Business Suite is at risk due to vulnerabilities discovered in December last year, and which could give attackers full control over a company's enterprise resource planning solution.

Collectively called PAYDAY, the flaws were found by Onapsis Research Labs and patches were initially issued by Oracle in April 2018. Subsequent flaws were patched a year later.

However, at this stage, about 21,000 Oracle EBS customers are estimated to be at risk since the PAYDAY flaws exist in all versions of the software, Onapsis researcher Sebastian Bortnik said in a blog post.

"The severity... is evident from the significance of ERP systems such as Oracle to global business function; 77% of global revenue will pass through an ERP system at some point, of which Oracle’s 21,000 EBS customers are just a proportion," Bortnik said.

"These vulnerabilities can only be mitigated by applying security patches. Onapsis estimates that 50% of Oracle EBS customers have not deployed the patches."

In a detailed report on the flaws, Onapsis said leaving them unaddressed could also mean that companies did not meet compliance standards required by different countries.

"From a Data Privacy standpoint (GDPR, CCPA, HIPAA, etc.), this vulnerability could allow an attacker to get personally identifiable information (PII) from the systems. This is the type of risk that usually makes executives and boards concerned about the possibility of a breach and a subsequent penalty if not properly addressed," the Onapsis report said.

Commenting on the vulnerabilities, Piyush Pandey, chief executive of ERP data security vendor Appsian, said: “Unfortunately, hackers are aware that traditional ERP systems lack the granular logging and analytics features required to detect unauthorised activity.

"Having a vulnerability that exploits a customer who may not be current on their security updates raises the risk of a data breach exponentially. Organisations must take additional steps to enhance their levels of visibility and control over their ERP data - and all of the user activity taking place around it."

Update, 25 November: Contacted for comment, Eric Maurice Oracle senior director, Global Product Security, said: “The security issues discussed in this paper have all been addressed in Oracle’s Critical Patch Update. Oracle encourages customers to follow the secure configuration recommendations in its deployment guides, remain on actively-supported versions, and apply Critical Patch Updates without delay.

"Unfortunately, Oracle continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches. In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches.

"At the time of the publication of this report, the most recent Critical Patch Update was the October 2019 Critical Patch Update."


26-27 February 2020 | Hilton Brisbane

Connecting the region’s leading data analytics professionals to drive and inspire your future strategy

Leading the data analytics division has never been easy, but now the challenge is on to remain ahead of the competition and reap the massive rewards as a strategic executive.

Do you want to leverage data governance as an enabler?Are you working at driving AI/ML implementation?

Want to stay abreast of data privacy and AI ethics requirements? Are you working hard to push predictive analytics to the limits?

With so much to keep on top of in such a rapidly changing technology space, collaboration is key to success. You don't need to struggle alone, network and share your struggles as well as your tips for success at CDAO Brisbane.

Discover how your peers have tackled the very same issues you face daily. Network with over 140 of your peers and hear from the leading professionals in your industry. Leverage this community of data and analytics enthusiasts to advance your strategy to the next level.

Download the Agenda to find out more


Sam Varghese

website statistics

Sam Varghese has been writing for iTWire since 2006, a year after the site came into existence. For nearly a decade thereafter, he wrote mostly about free and open source software, based on his own use of this genre of software. Since May 2016, he has been writing across many areas of technology. He has been a journalist for nearly 40 years in India (Indian Express and Deccan Herald), the UAE (Khaleej Times) and Australia (Daily Commercial News (now defunct) and The Age). His personal blog is titled Irregular Expression.



Recent Comments