New Security Features in Oracle E-Business Suite 12.2



Similar documents
Security Implications of Oracle Product Desupport April 23, 2015

Out of the Fire - Adding Layers of Protection When Deploying Oracle EBS to the Internet

How to Audit the Top Ten E-Business Suite Security Risks

Oracle Enterprise Manager 12c Cloud Control for Managing Oracle E-Business Suite 12.2

Oracle Database Security Myths

Credit Cards and Oracle E-Business Suite Security and PCI Compliance Issues

Oracle E-Business Suite APPS, SYSADMIN, and oracle Securing Generic Privileged Accounts. Stephen Kost Chief Technology Officer Integrigy Corporation

Integrigy Corporate Overview

AppDefend Application Firewall Overview

Securing Oracle E-Business Suite in the Cloud

R12.2 Install/Patch/Maintain Oracle E-Business Suite

Encrypting Sensitive Data in Oracle E-Business Suite

Guide to Auditing and Logging in the Oracle E-Business Suite

Oracle E-Business Suite (EBS)

Developing Value from Oracle s Audit Vault For Auditors and IT Security Professionals

Managing Oracle E-Business Suite Security

New Oracle 12c Security Features Oracle E-Business Suite Perspective

PCI Compliance in Oracle E-Business Suite

mission critical applications mission critical security Internal Auditor Primer: Oracle E-Business Suite Security Risks Primer

AppSentry Application and Database Security Auditing

WHITE PAPER: TECHNICAL. Symantec High Availability Solution for Oracle e-business Suite

All Things Oracle Database Encryption

Oracle E-Business Suite (R12) Integration with OID/OAM 11g

Managing R12 EBS using OEM with the Application Management and Application Change Management Packs

PCI Compliance in Oracle E-Business Suite

Upgrade Oracle EBS to Release Presenter: Sandra Vucinic VLAD Group, Inc.

Detecting and Stopping Cyber Attacks Against Oracle Databases June 25, 2015

Obtaining Value from Your Database Activity Monitoring (DAM) Solution

Oracle WebLogic Server 11g: Administration Essentials

The Weakest Link : Securing large, complex, global Oracle ebusiness Suite solutions

Oracle EBS Release 12.2 from A to Z. Real Experience of a Technical Upgrade

Oracle Health Sciences Network. 1 Introduction. 1.1 General Security Principles

Top Ten Fraud Risks in the Oracle E Business Suite

Oracle Application Express and Oracle E-Business Suite. Love and Mariage!

Release System Administrator s Guide

Web Application Security Assessment and Vulnerability Mitigation Tests

A webcast presented by IT Convergence November 20 th, 2014

Configuring Apache HTTP Server as a Reverse Proxy Server for SAS 9.3 Web Applications Deployed on Oracle WebLogic Server

How To Install An Org Vm Server On A Virtual Box On An Ubuntu (Orchestra) On A Windows Box On A Microsoft Zephyrus (Orroster) 2.5 (Orner)

1 Copyright 2011, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 8

Discoverer 11g for Oracle ebusiness Suite Partnering for Sucess

Credit Cards and Oracle: How to Comply with PCI DSS. Stephen Kost Integrigy Corporation Session #600

Oracle E-Business Suite Single Sign On Using Oracle Access Manager

Robert Honeyman Honeyman IT Consulting.

DEPLOYMENT GUIDE Version 1.0. Deploying F5 with the Oracle Fusion Middleware SOA Suite 11gR1

Brocade Virtual Traffic Manager and Oracle Enterprise Manager 12c Release 2 Deployment Guide

Oracle IDM Integration with E-Business Suite & Middleware Technologies

OBIEE 11g Security it s as easy as 1-2-3!

An Oracle White Paper June Security and the Oracle Database Cloud Service

HOW TO CONFIGURE PASS-THRU PROXY FOR ORACLE APPLICATIONS

WHITE PAPER. Guide to Auditing and Logging in the Oracle E-Business Suite

Banner Payment Processor Connection Handbook. December 2011

Release 12 Apps DBA 101. John Stouffer Independent Consultant

Oracle Fusion Middleware

Copyright 2013, Oracle and/or its affiliates. All rights reserved.

WHITE PAPER. Guide to Auditing and Logging in the Oracle E-Business Suite

Integrating OID/SSO with E- Business Suite and Third-Party SSO Solutions. Presented by Paul Jackson (Norman Leach)

An Oracle White Paper October Frequently Asked Questions for Oracle Forms 11g

linux20 (R12 Server) R Single Node SID - TEST linux1 (10gAS Server) Oracle 10gAS ( ) with OID SID - asinf server name

System Management. What are my options for deploying System Management on remote computers?

05.0 Application Development

1 Copyright 2011, Oracle and/or its affiliates. All rights reserved.

Detecting and Stopping Cyber Attacks against Oracle Databases

A Beginners Guide to Fusion Middleware

Monitoring Oracle Enterprise Performance Management System Release Deployments from Oracle Enterprise Manager 12c

Release 12 Apps DBA 101. John Stouffer Independent Consultant

Copyright 2012, Oracle and/or its affiliates. All rights reserved.

Kenna Platform Security. A technical overview of the comprehensive security measures Kenna uses to protect your data

Securing SAS Web Applications with SiteMinder

Oracle WebLogic Foundation of Oracle Fusion Middleware. Lawrence Manickam Toyork Systems Inc

LOAD BALANCING TECHNIQUES FOR RELEASE 11i AND RELEASE 12 E-BUSINESS ENVIRONMENTS

MEGA Web Application Architecture Overview MEGA 2009 SP4

What is Web Security? Motivation

Configuring Apache HTTP Server as a Reverse Proxy Server for SAS 9.2 Web Applications Deployed on BEA WebLogic Server 9.2

Configuring CQ Security

[1]Oracle Communications Billing and Revenue Management Web Services Manager Release 7.5 E

IBM. Vulnerability scanning and best practices

Driver for Oracle E-Business Suite (User Management, HR, and TCA) Implementation Guide

JVA-122. Secure Java Web Development

IBM Security QRadar Vulnerability Manager Version User Guide

Ellucian Recruiter Installation and Integration. Release 4.1 December 2015

PUBLIC Installation: SAP Mobile Platform Server for Linux

Deployment patterns for Fusion Middleware. a best practice session by Simon Haslam & Jacco H. Landlust

Load Balancing Oracle Web Applications. An Oracle White Paper November 2004

<Insert Picture Here> Application Testing Suite Overview

Copyright 2014, Oracle and/or its affiliates. All rights reserved.

Exploring Oracle E-Business Suite Load Balancing Options. Venkat Perumal IT Convergence

HP Application Lifecycle Management

Configuring Nex-Gen Web Load Balancer

How to Manage a Successful R12 Upgrade and Overcome the Challenges: Methodology and Tips that Work

Information Technology Policy

FileCloud Security FAQ

Brocade Virtual Traffic Manager and Oracle EBS 12.1 Deployment Guide

Installation Guide. Release 3.1

Integrating Apex into Federated Environment using SAML 2.0. Jon Tupman Portalsoft Solutions Ltd

REDCap Technical Overview

BlackBerry Enterprise Service 10. Version: Configuration Guide

Secret Server Qualys Integration Guide

Transcription:

New Security Features in Oracle E-Business Suite 12.2 October 24, 2013 Stephen Kost Chief Technology Officer Integrigy Corporation Phil Reimann Director of Business Development Integrigy Corporation

About Integrigy ERP Applications Oracle E-Business Suite Databases Oracle and Microsoft SQL Server Products Services AppSentry ERP Application and Database Security Auditing Tool AppDefend Enterprise Application Firewall for the Oracle E-Business Suite Validates Security Protects Oracle EBS Verify Security Ensure Compliance Build Security Security Assessments ERP, Database, Sensitive Data, Pen Testing Compliance Assistance SOX, PCI, HIPAA Security Design Services Auditing, Encryption, DMZ You

Agenda Oracle EBS 12.2 Overview Weblogic Q&A 1 2 3 4 5 Application Security Web Security

Agenda Oracle EBS 12.2 Overview Weblogic Q&A 1 2 3 4 5 Application Security Web Security

Plans to Upgrade to 12.2? What is your organization's position on upgrading to R12.2? 0% 10% 20% 30% 40% 50% Plan to upgrade within 0-12 months 13% Plan to upgrade within 12-24 months 14% We do not plan to upgrade 12% We have not made a decision. 42% No Answer 18%

Oracle 12.2 Architecture Simplified Oracle Fusion Middleware 11g WebLogic Server Client Browser https Oracle HTTP Server = Apache 2.0 WebLogic JSP UIX 11g BC4J APPS Oracle 11gR2 Database BI Publisher 10.1.2 Form 10.1.2 In 12.2, Oracle Application Server 10g is replaced with Oracle Fusion Middleware 11g, which includes WebLogic Server. All control and management is done using the Oracle Fusion Middleware control.

12.2 Online Patching Oracle E-Business Suite 12.2 environment has become much more complex with on-line patching. Database uses Edition-Based Redefinition and two full installs of the application server stack. Run Install EBSapps -> 10.1.2 3 Stop Run and make Patch the new Run Patch Install EBSapps -> 10.1.2 EBSapps -> APPL_TOP EBSapps -> COMMON_TOP Oracle 11gR2 Database 2 EBSapps -> APPL_TOP EBSapps -> COMMON_TOP FMW_Home Edition-Based Redefinition FMW_Home INST_TOP INST_TOP 4 Synchronize Run and Patch for next time 1 Patches applied to the Patch Install

12.2 AutoConfig Impact Configuration Changes Fusion Middleware Control WLS Administration Console Oracle Application Manager & Autoconfig Database Home SID name, Listener, dbports, etc Oracle HTTP Server Performance directives, log configuration, ports, mod_perl, mod_wl_ohs, etc. WebLogic Server oacore, oafm, forms and forms-c4ws services Classpath and JVM arguments for oacore E-Business Suite Concurrent Processing, Profile Options, Developer 10g, Product Specific Settings

Agenda Oracle EBS 12.2 Overview Weblogic Q&A 1 2 3 4 5 Application Security Web Security

Flexfield Value Set Security Who can view, insert, or update values for a particular value set in the Segment Values form - Adds segregation of duties to maintenance of flexfield value sets - Enabled by default - Access must be explicitly granted - Access can be based on user, responsibility, role, application, or operating unit

Flexfield Value Set Security Example Improve segregation of duties by allowing (1) certain users to only view or insert values for Account Flexfields and no other value sets, (2) certain users to only view or insert values for any HR application, and (3) certain users to only view or insert values for a specific operating unit. Roles and responsibilities are also supported. GL Super Users System Administrator Responsibility HR Super Users Accounting Flexfield FND Value Sets HR Flexfield Value Sets

Flexfield Value Set Security Additional Patches Required - Requires the mandatory Patch 17305947:R12.FND.C Additional Setup Required - All values sets locked upon install or upgrade until setup completed - Release 12.2 Flexfield Value Set Security Documentation Update for Patch 17305947:R12.FND.C (MOS Note ID 1589204.1) - MOS Note supersedes 12.2 Flexfields Guide

Allowed JSP Lists A whitelist of allowed JSP pages. Basically is DMZ URL Firewall for internal access. Oracle 12.2 Application Server Java Server Pages (JSP) 16,078 JSP pages OA Framework (OA/RF.jsp) 11,600 pages Client Browser https Apache OC4J Core Servlets 30 servlet classes APPS Database Web Services Servlets 70 servlet classes Oracle Forms 3,000 forms

Allowed JSP Lists Explicit list of allowed JSP pages Limits access to unused JSP pages for modules not configured or licensed Must be manually enabled See the Oracle EBS Security Guide manual for instructions on usage

Allowed JSP Lists Allowed JSP Lists disabled by default New profile option to allow for disabling of Allow JSP Lists Profile Option Name Description Allow Unrestricted JSP Access (FND_SEC_ALLOW_JSP_UNRESTRICTED_ACCESS) Set at Site or Server Level Yes Allow all JSPs (default) No Use Allowed JSP Lists

Standard allowed_jsps.conf # $Header: allowed_jsps.conf 120.0.12020000.3 2013/06/11 21:37:29 srveerar noship $ /OA_HTML/AppsLocalLogin.jsp /OA_HTML/cabo/jsps/a.jsp /OA_HTML/cabo/jsps/frameRedirect.jsp /OA_HTML/fndgfm.jsp /OA_HTML/jsp/fnd/close.jsp /OA_HTML/jsp/fnd/fnderror.jsp /OA_HTML/OADownload.jsp /OA_HTML/OAErrorDetailPage.jsp /OA_HTML/OAErrorPage.jsp /OA_HTML/OAExport.jsp /OA_HTML/OA.jsp /OA_HTML/OALogout.jsp /OA_HTML/OARegion.jsp /OA_HTML/RF.jsp /OA_HTML/GWY.jsp /OA_HTML/runforms.jsp /OA_HTML/xdo_doc_display.jsp /OA_HTML/OAD.jsp /OA_HTML/OAP.jsp include allowed_jsps_fin.conf include allowed_jsps_hr.conf include allowed_jsps_leasing.conf include allowed_jsps_procurement.conf include allowed_jsps_scm.conf include allowed_jsps_crm.conf include allowed_jsps_vcp.conf include allowed_jsps_diag_tests.conf

Default Passwords Fresh Install Of 191 database accounts, only default password is APPLSYSPUB/PUB Sets Weblogic control password Sets APPS and APPLSYS passwords Sets SYS, SYSTEM, CTXSYS, OUTLN, and 9 other standard database account passwords Sets accounts for all EBS product schemas 161 total accounts

Default Passwords Upgrade New database accounts will be added during the database upgrade for new application modules based on from what version you are upgrading from. Be sure to check these accounts for default passwords. Version Upgrade From New Database Accounts 11.5.10 XLE ASN FUN FPA ZX LNS IA XDO 12.0.0 JMF GMO IBW IPM DNA 12.0.4 IZU 12.1.0 RRS DPP MTH QPR DDR INL 12.2.2 GHG APPS_NE

Agenda Oracle EBS 12.2 Overview Weblogic Q&A 1 2 3 4 5 Application Security Web Security

WebLogic/Fusion Middleware Control Demonstration

Agenda Oracle EBS 12.2 Overview Weblogic Q&A 1 2 3 4 5 Application Security Web Security

Clickjacking Protection Frame Busting - Provides protection against clickjacking by disallowing OA Framework pages from being embedded into frames from thirdparty sites - Enabled by default Profile Option Name Description FND: Disable Frame Busting (FND_DISABLE_FRAME_BUSTING) Set at Site or Server Level True Disable frame busting False Use frame busting (default)

Clickjacking Protection X-Frame-Options HTTP response header - Now enabled for all Oracle EBS web pages and configured in the Apache httpd.conf - Enabled by default

Attachment Virus Scanning Enhanced virus scanning of all attachments and file uploads - Limited to Symantec server - Can be enabled or disabled at site, responsibility, application or user level with FND: Disable Virus Scan - OA Framework customizations can selectively enable or disable virus scanning - Virus scanning should be utilized when implementing irecruitment or isupplier

Additional Web Application Security Cookie Domains - Protects the Oracle EBS session cookie from web-based attacks - Set to domain by default in profile option ICX_SESSION_COOKIE_DOMAIN Cross-site Scripting (XSS) Protections - Check file uploads and attachments for XSS - XSS checking in Messaging Rich Text Editor - Use AntiSamy library for XSS filtering

Security Concerns Delivery Manager report output - Send reports to EBS users through e-mail - Upload reports to an FTP server - Save reports to the local file system of the EBS application tier SOA and Web Services (REST) - Do your DBA and security teams understand web services and how to properly secure them?

Security Concerns Encrypted vs. Non-Reversible Hashed Application Passwords - Default for EBS application accounts is still encrypted passwords vs. non-reversible hashed passwords

Agenda Oracle EBS 12.2 Overview Weblogic Q&A 1 2 3 4 5 Application Security Web Security

References Database Initialization Parameters for Oracle E-Business Suite Release 12 (Doc ID 396009.1) Oracle E-Business Suite Product Specific Release Notes, Release 12.2.2 (Doc ID 1585844.1) Oracle Application Framework Profile Options Release 12.2 (Doc ID 1373537.1)

Contact Information Stephen Kost Chief Technology Officer Integrigy Corporation web: www.integrigy.com e-mail: info@integrigy.com blog: integrigy.com/oracle-security-blog youtube: youtube.com/integrigy Copyright 2013 Integrigy Corporation. All rights reserved.