-------------- "Erman Arslan's Oracle Forum is available now. Click here to ask a question. " --------------
Thursday, July 29, 2021
Forum is back online ! -- Erman Arslan's Oracle Forum --
Planned Outgage ! -- Erman Arslan's Oracle Forum --
Our forum is being migrated to its new host at the moment.
Erman Arslan's Oracle Forum will be available soon. Thanks for your understanding and patience...
Note that, due to the short vacation, the questions piled up a bit. I will answer them all, once our forum will be reachable again.
Friday, July 9, 2021
Erman Arslan's Oracle Forum / Jun 1 2021 - July 7 2021 - "Questions and Answers Series"
Question: How much time do you spend/lose?
Just click on the link named "Erman Arslan's Oracle Forum is available now.
Click here to ask a question", which is available on the main page of Erman Arslan's Oracle Blog
Do not forget to read the blog posts too :)
Recoverability Roadmaps & Remediation Options - Oracle, Systems, Apps Technology, Virtualization and Engineered Systems
In this post, I want to share my thoughtson Recoverability, actually my approach that I use in Recoverability Assessments.. Actually, these types of assessments are comprehensive, they even include DR solutions, trainings, recovery processes and the continuous availability.
I start with the readiness.. Readiness in 3 different areas : People, Process and Technology. I review and rank the readiness for key areas that are enablers for availability, resiliency and recoverability by assessing current IT capabilities of the customer.
Once I generate the readiness documents, I do my analysis, determine the gaps and then present my recommendations. I support the customer in execution as well.. ( if they need me there..)
So it is pretty straight forward, but still requires lots of efforts :)
The assesments starts with the information gathering. I just gather the detailed information and do my analysis for a number of attributes in the following areas;
Operational Staff, Response Plans, Recovery Testing, Program Maintenance, Business Expectations, Production & DR Facilities, Application Infrastructure, Data Restoration and Recovery Network.
During this first phase, we usually meet with the customers. I write down the people, process, and techonology findings. Then, we popuplate tool based discovery reports ( DB , Server, SAN healtchecks, Server grabs & logs etc..)
In the second phase, I create a recommendation list. Next, I do the remediation roadmap, finalize the recoverability assessment document and lasty I give the final recoverability assessment repsentation (an executive presentation actually)
While analyzing the people and process findings, I check to see if there any any gaps in the following areas; business expectations, production & DR facilities, Application Infra, Data Restoration, Recovery network , Operational Staff, Reponse plan, Recovery Testing, Program maintanence and etc..
Following is an example of the GAPs that may be found in the Recovery network ;
No formal DR programDR requirements unknown
Lack of formal documented policies or processes
Finally I create thre recoverabiliy roadmap and that's it :)
Thursday, July 8, 2021
OVM Manager / Weblogic -- CVE-2019-2725 / deserialization - remote code execution vulnerability
Disable access to“/_async/*” and “/wls-wsat/” URLs on weblogic.
Test well..
MOS References:
Upgrading products bundled with Oracle VM Manager (Doc ID 2195205.1)
Security Alert CVE-2019-2725 Patch Availability Document for Oracle WebLogic Server (Doc ID 2535708.1)