ISC StormCast for Thursday, October 17th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 17 October 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, October 17th, 2019 edition of the Sandswit Stormsaurus, Stormcast. |
| 0:08.0 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:14.0 | Oracle today released its quarterly critical patch update or short CPU with 219 different security patches. |
| 0:25.4 | Now the first thing I always look for here is Java. |
| 0:30.4 | Java actually well not all that important it seems like this around, there are a good number of vulnerabilities |
| 0:39.6 | being addressed, but the largest CBSS base score is 6.8. The only vulnerability with the |
| 0:48.8 | maximum score of 10.0 is 1 in Oracle's no SQL database. This is exploitable via HTTP and could lead, of course, |
| 1:01.4 | to a complete system compromise. Certainly take a look at this patch, but we have a number of |
| 1:08.6 | other vulnerabilities in the high 9s. |
| 1:12.2 | For example, in the Oracle Construction Engineering Risk Matrix product, there are 3 9.8 vulnerabilities. |
| 1:22.8 | Two of which are in Jackson Databind, which is the same issue that affected the NoSQL database. |
| 1:29.6 | The third one is an Apache Tomcat vulnerability that actually goes back to 2017. |
| 1:37.2 | And that's sadly always a little bit of a theme here that we have some critical vulnerabilities |
| 1:42.7 | that are essentially quite old and come from included |
| 1:48.1 | open source components. For example, there are still some log 4J issues that are being addressed, |
| 1:54.5 | also a problem with the Apache Commons. That's the file upload vulnerability that's also at least a year old, I think. |
| 2:03.6 | Now, many of the critical vulnerabilities in this update are related to this Jackson |
| 2:09.6 | data bind vulnerability. |
| 2:10.6 | So a little bit more about this. |
| 2:13.6 | This is actually part of the Jackson Project. |
| 2:16.6 | That's a JSON library for Java and this particular vulnerability is a deserilization issue. |
| 2:25.5 | We of course had many of them before and this library does, well, what's always hard to |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

