Application Security

8/30/2017
07:50 PM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

Execs Underestimate Risks to Oracle EBS

It's another sign that ERP keeps getting short shrift on the security front.

A new survey out today shows that C-level executives are underestimating the risks to their Oracle E-Business Suite (EBS) applications, despite being critical to the organizations that depend on them. It's the latest indicator of a long-running trend of enterprises ignoring threats to enterprise resource planning (ERP) systems, which tend to be intertwined with the core processes responsible for financial and operational success.

Released today by Ponemon Institute, the study polled 600 IT security experts about their organizations' Oracle EBS risk postures. Oracle EBS includes systems for financial management, personnel management, customer management, and supply chain management, among myriad other critical functions. According to the experts at Panorama Consulting, Oracle holds about 13% market share in the ERP market — a growing category that analysts expect to reach $49.5 billion by the end of the decade.

Key to today's findings are the fact that at the same time 70% of security and IT leaders believe their organization is susceptible to a major breach because of insecure Oracle EBS applications, 67% report that their senior line-of-business leaders aren't aware of that. Approximately 73% of survey respondents said C-level executives underestimate the risk of insecure Oracle EBS applications.

This temperature check confirms what a lot of ERP security experts have warned over the last several years: that enterprises are spending great sums on security and patch management for ho-hum applications without providing the same investment and care for some of the most critical applications in their technology stack.

The report today shows that one in five organizations apply security patches only with functional upgrades, and fewer than half of them have a monthly plan to implement security patches to Oracle EBS applications. It's a scary thought given the kinds of ERP vulnerabilities that are coming to light with increasing frequency these days.

"Oracle EBS represents the perfect economic target for cybercrime organizations and nation-state hackers and, compounding the problem, vulnerabilities to these applications are on the rise," says Mariano Nunez, CEO of Onapsis, which sponsored the report. 

For example, just last month Oracle released a patch for a vulnerability found by Onapsis that would make it possible for attackers to steal documents such as invoices, purchase orders, financial reports, customer information, and internal communication without requiring a valid user account. This flaw is likely exploitable over the Internet, and it's not alone. Onapsis reports a 46% increase in 2017 vulnerabilities within Oracle EBS compared to 2016 year-to-date.

And this is just one vendor among many, including the other ERP behemoth, SAP. A survey out earlier this year from ERPScan found that 89% of security professionals believe the number of cyber attacks against ERP systems will grow.

"Most enterprises are still unprepared for attacks against ERP systems," says Alexander Polyakov, CTO for ERPScan. "ERP systems store and manage essential business information and processes. CISOs should include this area in their list of top priorities if they haven't done it yet."

Related Content:

 

Learn from the industry’s most knowledgeable CISOs and IT security experts in a setting that is conducive to interaction and conversation. Click for more info and to register.

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
WebAuthn, FIDO2 Infuse Browsers, Platforms with Strong Authentication
John Fontana, Standards & Identity Analyst, Yubico,  9/19/2018
Turn the NIST Cybersecurity Framework into Reality: 5 Steps
Mukul Kumar & Anupam Sahai, CISO & VP of Cyber Practice and VP Product Management, Cavirin Systems,  9/20/2018
NSS Labs Files Antitrust Suit Against Symantec, CrowdStrike, ESET, AMTSO
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-1664
PUBLISHED: 2018-09-25
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 echoing of AMP management interface authorization headers exposes login credentials in browser cache. ...
CVE-2018-1669
PUBLISHED: 2018-09-25
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote atta...
CVE-2018-1539
PUBLISHED: 2018-09-25
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561.
CVE-2018-1560
PUBLISHED: 2018-09-25
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr...
CVE-2018-1588
PUBLISHED: 2018-09-25
IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resourc...