With OPatch version 22.214.171.124.36 for databases (and version 126.96.36.199.11 for Middleware), a new utility was included: obfuscate.
This utility was released to workaround the increased security needed around databases servers. We cannot escape having vulnerability scanners to run there. These vulnerability scanners sometimes do not distinguish between used and unused files.
When patching a database, backup copy of the modified files are kept in $ORACLE_HOME/.patch_storage. Their hash sometime trigger the vulnerability scanners and says – 🚨server not patched ⚠️. Which is misleading.
Starting with OPatch 188.8.131.52.36, released together with the January 2023 Release Update, the backup of patch files are automatically obfuscated.
The new “opatch util obfuscate” allows to do the same for older patches. Let’s see how it works.Read More