Blog|Login|Chinese German Japanese|Follow @imperva
April 30, 2009
 Oracle's Security Bugs, Now on DB2?
bridge.JPG

Last week, while we were all busy at the RSA, IBM announced a new version of DB2: version 9.7 will be available in June. From my initial assessment of the information that is shared via the IBM web site and other sites/blogs (here, here and here)  and it looks very promising (I will not keep the list of all the new features). 


A very good analysis was written by Merv Adrian at BeyeNETWORK.He highlighted the fact that DB2 9.7 can now run PL/SQL. Natively. In the engine. 

Donald Feinberg from Gartner thinks that IBM DB2 9.7 shakes up the DBMS market with this functionality:

A feature in the IBM DB2 9.7 that will enable users to more easily replace the Oracle
database management system with the DB2 DBMS has important implications for the
commercial, off-the-shelf software applications community.


He also adds that this compatibility feature will enable Oracle applications to run natively on DB2:

In discussions with Gartner, reference customers tell us that DB2 runs 95% or more of Oracle specific functionality found in SQL statements and natively runs PL/SQL, Oracle's stored procedure language. This is native functionality; it is not an emulator, nor does it require changes to the application code (other than the 5%, which is mostly minor functionality, not found in many applications). In addtion, the organization must also address the migration for data from Oracle to DB2.


WOW,  running PL/SQL on DB2. Think about the security implications. There are many documented vulnerabilities (Google this and that )  and other to come. 

It's going to be very interesting to see how customers will address those challenges. 

Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.

« The Spicy Food Challenge #3 | Main | SQL Injection Demonstration Video Part 1 »