David Litchfield
![David Litchfield](/assets/img/authors/unknown.jpg)
David Litchfield
David Litchfieldis a security expert from the United Kingdom. Anne Saita, writing for Information Security Magazine, called him along with his brother Mark Litchfield, "World's Best Bug Hunters" in December, 2003...
database goes id interact internet user web
Someone can come in off the Internet over the Web without a user ID or password and interact with the back-end database server, so it goes through all the firewalls. This is critical.
case fixed flaw january last neglected oracle risks serious trivial
We disclosed this to Oracle on Oct. 25 last year. Around the same time, they were alerted to another high-risk flaw that is not as serious as this one. They fixed that one in the January CPU but neglected to fix this. It's not a case of not having enough time, because the fix is trivial and the risks are severe.