Quote Originally Posted by davey23uk View Post
not everyone is regulated by the FSA either - and no there is no rule to apply patches just because they exist

there is a rule to protect the data
So when there is a known bug that doesn't require authentication, thenwe as good DBA's should apply the patch? So its balancing between allowing for new bugs, and leaving vulnerabilities unpatched in a database that could be exploited by someone nefarious.