A computer security expert believes that
nine in every ten Oracle databases are vulnerable to an attack that would give hackers access and control over sensitive corporate and government database systems, without the need for a user id or password. Litchfield said that he warned Oracle of the problem in November, hoping that the company would fix the flaw when it issued a group of quarterly security patches in January. He said that he decided to go public because Oracle failed to do so.
Officials with Oracle declined comment on the matter.