Oracle Database 12c 's Data Redaction feature - designed to automatically and in real-time protect sensitive database information - can be bypassed without much effort, according to security expert David Litchfield.
Litchfield, who works for Datacomm TSS, gave a presentation titled “Oracle Data Redaction Is Broken” at the DefConlast week.
The researcher informed the public that the service – which is supposed to protect sensitive data – is vulnerable, and that it does not require the use of complex methods to breach it.
The redaction feature is designed to automatically protect sensitive database material by either permanently hiding column data or partially masking it – for example, by revealing only the last four digits of social security numbers when a search query is run.
However, according to the researcher, this mechanism contains basic vulnerabilities, and its neutralization can be achieved through the injection of specific SQL queries.
During the presentation, Litchfield demonstrated how a remote attacker could assume the required privileges to access protected information.
You can view the researcher's full report here: https://packetstorm.foofus.com/papers/database/Oracle_Data_Redaction_is_Broken.pdf

