Personal tools
You are here: Home Oracle Security Blog Archive 2011

Entries For: 2011

November 01, 2011

Upcoming Webinar: Oracle Critical Patch Update October 2011 Database Impact

Oracle October 2011 CPU - Oracle Database Impact
Thursday, November 3, 2:00pm - 3:00pm EDT

Every quarter, Oracle releases a Critical Patch Update (CPU) that fixes a number of security vulnerabilities in the Oracle Database. This quarterly educational session will focus on the October 2011 CPU and the impact on the Oracle Database. The topics will include:
  • A review of the security vulnerabilities fixed in this CPU,
  • An analysis of the required CPU patches,
  • A discussion of patching including CPUs vs. PSUs.

Example vulnerabilities will be demonstrated in order to show how easy it is exploit many of the fixed security bugs.

Click here to register for the Oracle Database webinar.

October 25, 2011

Upcoming Webinar: Oracle Critical Patch Update October 2011 E-Business Suite Impact

Oracle October 2011 CPU - Oracle E-Business Suite Impact
Thursday, October 27, 2:00pm - 3:00pm EDT

Every quarter, Oracle releases a Critical Patch Update (CPU) that fixes a number of security bugs in all the Oracle products including the
• Oracle Database,
• Oracle Application Server,
• Oracle E-Business Suite.

These patches are large, complex, and often difficult to understand for the Oracle E-Business since multiple patches are required with some being cumulative and others needing prerequisites.

This quarterly eLearning session will focus on the October 2011 CPU and the impact on E-Business Suite environments.

Topics will include;
• a review of the security vulnerabilities fixed in the CPU,
• an analysis of the required CPU patches,
• a discussion of a high-level patch strategy.

Example vulnerabilities will be demonstrated in order to show how easy it is exploit many of the fixed security bugs.

Click here to register for this webinar.

September 23, 2011

Integrigy YouTube Channel

Integrigy is pleased to announce our new YouTube Channel .

Integrigy is pleased to announce our new YouTube Channel.  We will be posting videos of our webinars and short topics regarding database and application security.

The following videos are available from Integrigy Webinars -

  • Upgrade +1 - Improving your Security During Your Upgrade to R12 
  • Oracle April 2011 Critical Patch Update E-Business Suite Impact 
  • Internal Auditor Primer: Oracle E-Business Suite Security Risks 
  • Protecting Your Sensitive Data in the Oracle E-Business Suite
  • Upgrade Security in Your Oracle R12 Upgrade 
  • Oracle July 2011 Critical Patch Update Oracle Database Impact

Link: http://www.youtube.com/Integrigy

July 26, 2011

Upcoming Webinars: Oracle Critical Patch Update July 2011

Integrigy's CTO, Stephen Kost, will be presenting a series of webinars on Oracle's Critical Patch Update for July 2011.

Oracle July 2011 CPU - Oracle E-Business Suite Impact
Thursday, July 28, 2:00pm - 3:00pm EDT

This quarterly eLearning session will focus on the July 2011 CPU and the impact on E-Business Suite environments.

Topics will include;
  • a review of the security vulnerabilities fixed in the CPU,
  • an analysis of the required CPU patches,
  • a discussion of a high-level patch strategy.

Example vulnerabilities will be demonstrated in order to show how easy it is exploit many of the fixed security bugs.

Click here to register for the Oracle E-Business Suite webinar.


Oracle July 2011 CPU - Oracle Database Impact

Tuesday, August 2, 2:00pm - 3:00pm EDT

Every quarter, Oracle releases a Critical Patch Update (CPU) that fixes a number of security vulnerabilities in the Oracle Database. This quarterly eLearning session will focus on the July 2011 CPU and the impact on the Oracle Database. The topics will include:
  • A review of the security vulnerabilities fixed in this CPU,
  • An analysis of the required CPU patches,
  • A discussion of patching including CPUs vs. PSUs.

Example vulnerabilities will be demonstrated in order to show how easy it is exploit many of the fixed security bugs.

Click here to register for the Oracle Database webinar.

July 17, 2011

Oracle Critical Patch Update July 2011 Pre-Release Analysis

Here is a brief analysis of the pre-release announcement for the upcoming July 2011 Oracle Critical Patch Update (CPU) -
  • Overall, 55 Oracle security vulnerabilities (non-Solaris bugs) are fixed in this CPU, which is an above average number but well within the range of previous CPUs (Apr-11=47, Jan-11=43, Oct-10=50, Jul-10=38, Apr-10=31, Jan-10=24, Oct-09=38, Jul-09=30, Apr-09=43, Jan-09=41, Oct-08=36, Jul-08=45, Apr-08=41, Jan-08=26, Oct-07=51, Jul-07=45, Apr-07=36, Jan-07=51, Oct-06=101, Jul-06=62, Apr-06=34, Jan-06=80).  These numbers have been normalized for Oracle products and excludes any Sun products.
  • The Oracle product and vulnerability mix appears to be similar to previous CPUs, with the only exception being a large number of Oracle Grid Control vulnerabilities fixed this quarter.  All CPU supported Oracle Database and Oracle E-Business Suite versions are included.  The list of supported versions is getting very short and should be carefully reviewed to determine if version upgrades are required prior to applying the CPU security patches -
        • Database = 10.1.0.5, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, 11.2.0.2 for major platforms
        • Application Server = 10.1.2.3.0, 10.1.3.5.0, 11.1.1.3.0, 11.1.1.4.0, and 11.1.1.5.0
        • E-Business Suite = 11.5.10.2, 12.04, 12.0.6, 12.1.1, 12.1.2, and 12.1.3
  • As anticipated by Integrigy, this is the first CPU available for Oracle Database 11.2.0.2.
  • For the Oracle E-Business, as of the July 2011 there is no CPU support for all versions prior to 11.5.10.2 and 12.0.0 - 12.0.5.  We are not sure if it is a mistake in the CPU, but 12.0.4 is listed as a supported version.  11.5.10.2 requires the "Minimum Baseline for Extended Support" as specified in Metalink Note ID 883202.1.
  • Based on the pre-release announcement, few determinations can be made as to the actual severity and impact on most organizations because of the varied components being patched this quarter.  For the database, the highest CVSSv2 score is a 7.2 and 2 vulnerabilities are remotely exploitable without authentication.  However, since 18 components are listed as being patched for the 13 vulnerabilities, it is hard to determine the impact without more details regarding individual vulnerabilities.  We anticipate the highest scoring vulnerabilities will be the client-side and Database Vault vulnerabilities.
  • Integrigy will be presenting more information on this CPU in the following webinars: (1) Oracle July 2011 CPU E-Business Suite Impact Webinar Thursday, July 28, 2pm ET and (2) Oracle July 2011 CPU Oracle Database Impact Webinar Tuesday, August 2, 2pm ET.

Oracle Database
  • There are 13 database vulnerabilities; 2 are remotely exploitable without authentication and 2 are applicable to client-side only installations.
  • Since at least one database vulnerability has a CVSS 2.0 metric of 7.1 (important to high for a database vulnerability), this is a fairly important CPU.
  • The components fixed by this CPU are not the usual suspects and several will not be implemented in many environments.  It will be interesting to see what the actual vulnerabilities are in these components: CMDB Metadata & Instance APIs, Content Management, Core RDBMS, Database Target Type Menus, Database Vault, EMCTL, Enterprise Config Management, Enterprise Manager Console, Event Management, Instance Management, Oracle Universal Installer, Schema Management, Security Framework, Security Management, SQL Performance Advisories/UIs, Streams, AQ & Replication Mgmt, and XML Developer Kit.
  • In addition, there are 18 vulnerabilities in Oracle Enterprise Manager and 3 in Oracle Secure Backup.
Oracle Fusion Middleware
  • There are 7 new Oracle Fusion Middleware vulnerabilities, 2 of which are remotely exploitable without authentication with the highest CVSS score being 10.0.
  • All Oracle Fusion Middleware implementations should carefully review this CPU to determine the exact impact to your environment.

Oracle E-Business Suite 11i and R12
  • There is only one new Oracle E-Business Suite 11i and R12 vulnerability, which is remotely exploitable without authentication.  Most likely the Business Intelligence vulnerability cannot be exploited externally in DMZ implementations.

Planning Impact
  • We anticipate the criticality of this quarter's CPU will be in-line with previous CPUs.  Based on the patched components, this may be a lower than average risk CPU for specific databases based on configuration and installed options.  It appears most of the vulnerabilities are related to Enterprise Manager components.
  • As with all previous CPUs, this quarter's security patches should be deemed critical and you should adhere to the established procedures and timing used for previous CPUs.
  • For Oracle E-Business Suite customers, most likely the Business Intelligence will have to be applied to all implementations even if the Business Intelligence module is not installed, configured, or licensed.

Upcoming Integrigy CPU Webinars

Oracle July 2011 CPU E-Business Suite Impact
Thursday, July 28, 2pm ET

Oracle July 2011 CPU Oracle Database Impact
Tuesday, August 2, 2pm ET

July 08, 2011

Integrigy at OAUG Connection Point

The OAUG and NCOAUG Connection Point Release 12.1 conference is being held July 12-13, 2011 in Chicago.  This event is solely focused on Oracle E-Business Suite R12 and organizations planning on implementing R12 or have already upgraded.  Integrigy will be presenting on how to secure R12 and an approach to maximize the security of your R12 implementation while minimizing effort and cost.

Upgrade Security in Your Oracle R12 Upgrade
Stephen Kost, Integrigy, CTO
Tuesday, July 12, 2011
9:45am - 10:45am
Grand Ballroom III

If you are attending and would like to chat with one of our security experts about the latest developments in Oracle security or discuss specific security challenges you might be facing, drop us a note at info at integrigy.com and we can arrange to meet.  We have a few slots remaining, but they are filling up fast.
Categories:

May 09, 2011

Upcoming Webinar: Improve Security in Your Oracle R12 Upgrade

Improve Security in Your Oracle R12 Upgrade
Thursday, May 12, 2010 2:00 PM - 3:00 PM EDT

The upgrade from Oracle E-Business Suite (EBS) 11i to R12 is a unique opportunity to improve the security of your implementation by resolving existing security issues, configuring R12 securely, and taking advantage of new security features in R12.  This one hour education session will highlight R12 security changes and discuss a framework for a security focused R12 upgrade project.

Topics will include:

  • 11i and R12 differences and changes that impact security
  • R12 security enhancements and new features
  • Improving security throughout the R12 upgrade process

Click here to register for this webinar.

May 04, 2011

Upcoming Webinar: Oracle Critical Patch Update April 2010 - Oracle Database Impact

Oracle April 2010 CPU - Oracle Database Impact
Thursday, May 5, 2:00pm - 3:00pm EDT

Every quarter, Oracle releases a Critical Patch Update (CPU) that fixes a number of security vulnerabilities in the Oracle Database. This quarterly educational session will focus on the April 2010 CPU and the impact on the Oracle Database. The topics will include:
  • A review of the security vulnerabilities fixed in this CPU,
  • An analysis of the required CPU patches,
  • A discussion of patching including CPUs vs. PSUs.

Example vulnerabilities will be demonstrated in order to show how easy it is exploit many of the fixed security bugs.

Click here to register for the Oracle Database webinar.

April 14, 2011

Oracle Critical Patch Update April 2011 Pre-Release Analysis

Here is a brief analysis of the pre-release announcement for the upcoming April 2011 Oracle Critical Patch Update (CPU) -
  • Overall, 47 Oracle security vulnerabilities (non-Solaris bugs) are fixed in this CPU, which is an average number and well within the range of previous CPUs (Jan-11=43, Oct-10=50, Jul-10=38, Apr-10=31, Jan-10=24, Oct-09=38, Jul-09=30, Apr-09=43, Jan-09=41, Oct-08=36, Jul-08=45, Apr-08=41, Jan-08=26, Oct-07=51, Jul-07=45, Apr-07=36, Jan-07=51, Oct-06=101, Jul-06=62, Apr-06=34, Jan-06=80).  These numbers have been normalized for Oracle products and excludes any Sun products.
  • The Oracle product and vulnerability mix appears to be similar to previous CPUs.  All CPU supported Oracle Database and Oracle E-Business Suite versions are included.  The list of supported versions is getting very short and should be carefully reviewed to determine if version upgrades are required prior to applying the CPU security patches -
        • Database = 10.1.0.5, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, 11.2.0.2 for major platforms
        • Application Server = 10.1.2.3.0, 10.1.3.5.0, 11.1.1.2.0, 11.1.1.3.0, and 11.1.1.4.0
        • E-Business Suite = 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3
  • As anticipated by Integrigy, this is the first CPU available for Oracle Database 11.2.0.2.
  • For the Oracle E-Business, as of the April 2011 there is no CPU support for all versions prior to 11.5.10.2 and 12.0.0 - 12.0.5.  11.5.10.2 requires the "Minimum Baseline for Extended Support" as specified in Metalink Note ID 883202.1.
  • The highlight of this CPU is 6 of 9 Oracle Application Server/Fusion Middleware security vulnerabilities are remotely exploitable without authentication with the highest CVSSv2 score being 10.0.  The vulnerabilities are in Oracle Help, Oracle HTTP Server, Oracle JRockit, Oracle Outside In Technology, Oracle Security Service, Oracle WebLogic Server, Portal, and Single Sign On components.
  • Integrigy will be presenting more information on this CPU in the following webinars: (1) Oracle April 2011 CPU E-Business Suite Impact Webinar Thursday, April 28, 2pm ET and (2) Oracle April 2011 CPU Oracle Database Impact Webinar Thursday, May 5, 2pm ET.

Oracle Database
  • There are 6 database vulnerabilities and 2 are remotely exploitable without authentication.
  • Since at least one database vulnerability has a CVSS 2.0 metric of 6.5 (important to high for a database vulnerability), this is a fairly important CPU.
  • The components fixed by this CPU are not the usual suspects and several will not be implemented in many environments.  It will be interesting to see what the actual vulnerabilities are in these components: Application Service Level Management, Database Vault, Network Foundation, Oracle Help, Oracle Security Service, Oracle Warehouse Builder, and UIX.  If the Network Foundation bug is a denial of service and most of the other components are not implemented in an environment, this could be one of the first CPUs to be classified as low risk for some Oracle databases.
Oracle Fusion Middleware
  • There are 9 new Oracle Fusion Middleware vulnerabilities, 6 of which are remotely exploitable without authentication with the highest CVSS score being 10.0.
  • Of critical importance will be the fixes in the Oracle HTTP Server and Oracle Web Logic Server.  All Oracle Fusion Middleware implementations should carefully review this CPU to determine the exact impact to your environment.

Oracle E-Business Suite 11i and R12
  • There are 4 new Oracle E-Business Suite 11i and R12 vulnerabilities, two of which are remotely exploitable without authentication.
  • The vulnerabilities are Oracle Application Object Library (AOL), Applications Install, and Web ADI.  It is not clear if the AOL vulnerabilities can be exploited externally in DMZ implementations.

Planning Impact
  • We anticipate the criticality of this quarter's CPU will be in-line with previous CPUs.  The only exception may the significant number of Oracle Fusion Middleware remotely exploitable vulnerabilities, especially any in the Oracle HTTP Server.  For specific databases based on configuration and installed options, this may be a lower than average risk CPU.
  • As with all previous CPUs, this quarter's security patches should be deemed critical and you should adhere to the established procedures and timing used for previous CPUs.
  • Oracle E-Business Suite customers with externally facing implementations should carefully review the remotely exploitable vulnerabilities in Application Object Library to determine if these pages are blocked by the URL firewall.  If any of the vulnerable web pages are externally accessible, customers should look to immediately patch these environments.

Upcoming Integrigy CPU Webinars

Oracle April 2011 CPU E-Business Suite Impact
Thursday, April 28, 2pm ET

Oracle April 2011 CPU Oracle Database Impact
Thursday, May 5, 2pm ET

April 05, 2011

COLLABORATE11 - IOUG Operation Classified: Security Hackfest

For those of you not familiar with COLLABORATE or have not previously attended, the Oracle Applications Users Group (OAUG) and Independent Oracle Users Group (IOUG) have teamed together to host a user-driven event with exceptional content.  COLLABORATE11 is Sunday, April 10, 2011 through Thursday, April 14, 2011 in Orlando.  This year there will be over 1,000 technical sessions covering virtually every Oracle product.

For IOUG attendess, the reception on Sunday evening from 5-7pm has the theme "IOUG Operation Classified: Security Hackfest".  This event will pit your skills at securing and hacking the latest Oracle database and competition with your fellow attendees.

To help support the event, Integrigy has updated our highly regarded "Oracle Database Security Quick Reference" to included the latest security information for Oracle 11gR2. 

Note: This event is only open to IOUG attendees.

References:

Integrigy Oracle Database Security Quick Reference

Integrigy Oracle E-Business Suite Security Quick Reference

 

Categories:

Integrigy at COLLABORATE11

For those of you not familiar with COLLABORATE or have not previously attended, the Oracle Applications Users Group (OAUG) and Independent Oracle Users Group (IOUG) have teamed together to host a user-driven event with exceptional content.  COLLABORATE11 is Sunday, April 10, 2011 through Thursday, April 14, 2011 in Orlando.  This year there will be over 1,000 technical sessions covering virtually every Oracle product. 

If you are attending and would like to chat with one of our security experts about the latest developments in Oracle security or discuss specific security challenges you might be facing, drop us a note at info at integrigy.com and we can arrange to meet.  We have a few slots remaining, but they are filling up fast.

Integrigy's CTO, Stephen Kost, will be presenting four technical sessions on securing Oracle products and participating on a panel.

Oracle Applications Users Group (OAUG)


Protecting Sensitive Data in the Oracle E-Business Suite
Session #8680
Monday, April 11
10:30 am - 11:30 am

Securing the Oracle E-Business Suite Best Practices Panel
Session #4947
Monday, April 11
3:45 pm - 4:45 pm

Real-life E-Business Suite Security Mistakes
Session #8387
Wednesday, April 13
2:15 pm - 3:15 pm

Independent Oracle Users Group (IOUG)


IOUG Security Boot Camp: Real-life Database Security Mistakes
Session #715
Tuesday, April 12
9:15 am - 10:15 am

Credit Cards and Oracle: How to Comply with PCI-DSS
Session #Q600
Tuesday, April 12
11:45 am - 12:15 pm

See you in Orlando!

March 14, 2011

Webinar: Protecting Your Sensitive Data in Oracle E-Business Suite

Protecting You Sensitive Data in the Oracle E-Business Suite
Wednesday, March 16, 2011 2pm - 3pm EDT

To protect sensitive data (i.e. Social Security numbers)  in Oracle E-Business Suite environments, numerous Oracle technologies and third-party products promise to be your next silver bullet.  Compliance requirements, such as Payment Card Industry Data Security Standard (PCI-DSS), SOX, and HIPAA, require these types of solutions and technologies be implemented in order to protect sensitive data.  However, implementing these technologies is challenging and there are significant limitations and often certification issues to be considered.

During this hour-long webinar we will discuss best practices and share some client success stories for encryption, scrambling, and security auditing. Solutions range from simple SQL scripts to expensive add-on products.

Agenda:

  • An overview of Oracle E-Business Suite data security challenges
  • Sensitive data protection compliance requirements – PCI-DSS, SOX, HIPAA
  • Best practices and solutions for encrypting sensitive data
  • Best practices and solutions for scrambling data in test and development environments
  • Best practices and solutions for auditing sensitive data access

Click here to register for this webinar.

February 17, 2011

Webinar: Top Ten Fraud Risks in the Oracle E-Business Suite

Top Ten Fraud Risks in the Oracle E-Business Suite
Thursday, February 24, 2010 2:00 PM - 3:00 PM EST

Guarding against fraud within the Oracle E-Business Suite requires multiple actions on several fronts – within the ERP applications, written policies and procedures, and IT security.  Setting up roles and responsibilities to ensure segregation of duties, developing anti-fraud policies and procedures, and implementing effective monitoring are required.   IT Security must be implemented by installing rigorous controls and configurations, requiring operational best practices and procedures, and monitoring for fraudulent activities.

Please join us for this one hour educational webinar from ERP Risk Advisers and Integrigy to learn about the Top Ten Fraud Risks in the Oracle E-Business Suite.  

Topics to include:
  • Effective Segregation of Duties
  • Anti-Fraud Policies and Procedures
  • Meaningful Monitoring within the Applications
  • Monitoring for IT Security
  • Secure Passwords
  • Guarding Access to Data

Click here to register for this webinar.

January 17, 2011

Oracle Critical Patch Update January 2011 Pre-Release Analysis

Here is a brief analysis of the pre-release announcement for the upcoming January 2011 Oracle Critical Patch Update (CPU) -
  • Overall, 43 Oracle security vulnerabilities are fixed in this CPU, which is a average number and well within the range of previous CPUs (Oct-10=50, Jul-10=38, Apr-10=31, Jan-10=24, Oct-09=38, Jul-09=30, Apr-09=43, Jan-09=41, Oct-08=36, Jul-08=45, Apr-08=41, Jan-08=26, Oct-07=51, Jul-07=45, Apr-07=36, Jan-07=51, Oct-06=101, Jul-06=62, Apr-06=34, Jan-06=80).  These numbers have been normalized for Oracle products and excludes any Sun products.
  • The Oracle product and vulnerability mix appears to be similar to previous CPUs.  All CPU supported Oracle Database and Oracle E-Business Suite versions are included.  The list of supported versions is getting very short and should be carefully reviewed to determine if version upgrades are required prior to applying the CPU security patches -
        • Database = 10.1.0.5, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 for major platforms
        • Application Server = 10.1.2.3.0, 11.1.1.2.0, and 11.1.1.3.0
        • E-Business Suite = 11.5.10.x, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, and 12.1.3
  • The major versions no longer supported by Critical Patch Updates are Oracle Database 9.2.0.8 (July 2010) and Oracle Application Server/Fusion Middleware versions 10.1.3.5.0 and 11.1.1.1.
  • The highlight of this CPU is 12 of 16 Oracle Application Server/Fusion Middleware security vulnerabilities are remotely exploitable without authentication with the highest CVSSv2 score being 10.0.  The vulnerabilities are in Oracle BI Publisher, Oracle Discoverer, Oracle Document Capture, Oracle GoldenGate Veridata, Oracle HTTP Server, Oracle JRockit, Oracle Outside In Technology, Oracle WebLogic Server, and Services for Beehive components.
  • Integrigy will be presenting more information on this CPU in the following webinars: (1) Oracle January 2011 CPU E-Business Suite Impact Webinar Thursday, January 27, 2pm ET and (2) Oracle January 2011 CPU Oracle Database Impact Webinar Thursday, February 3, 2pm ET.

Oracle Database
  • There are 6 database vulnerabilities and 2 are remotely exploitable without authentication.
  • Since at least one database vulnerability has a CVSS 2.0 metric of 7.5 (practical maximum for a database vulnerability), this is a fairly important CPU.  Most likely, any database account, even a lowly privileged account, will be able to gain full-control of the database by exploiting the vulnerability.
  • The components fixed by this CPU are not the usual suspects and several will not be implemented in many environments.  It will be interesting to see what the actual vulnerabilities are in these components: Client System Analyzer, Cluster Verify Utility, Database Vault, Oracle Spatial, Scheduler Agent, and UIX.
Oracle Fusion Middleware
  • There are 16 new Oracle Fusion Middleware vulnerabilities, 12 of which are remotely exploitable without authentication with the highest CVSS score being 10.0.
  • Of critical importance will be the fixes in the Oracle HTTP Server and Oracle Web Logic Server.  All Oracle Fusion Middleware implementations should carefully review this CPU to determine the exact impact to your environment.

Oracle E-Business Suite 11i and R12
  • There are 2 new Oracle E-Business Suite 11i and R12 vulnerabilities, both of which are remotely exploitable without authentication.
  • The vulnerabilities are Oracle Application Object Library and Oracle Common Applications.  It is not clear if either of these modules can be exploited externally in DMZ implementations.

Planning Impact
  • We anticipate the criticality of this quarter's CPU will be in-line with previous CPUs.  The only exception may the significant number of Oracle Fusion Middleware remotely exploitable vulnerabilities, especially any in the Oracle HTTP Server.
  • As with all previous CPUs, this quarter's security patches should be deemed critical and you should adhere to the established procedures and timing used for previous CPUs.
  • Oracle E-Business Suite customers with externally facing implementations should carefully review the remotely exploitable vulnerabilities in Application Object Library to determine if these pages are blocked by the URL firewall.  If any of the vulnerable web pages are externally accessible, customers should look to immediately patch these environments.

January 10, 2011

Webinar: Upgrade Security in Your Oracle R12 Upgrade

Upgrade Security in Your Oracle R12 Upgrade
Thursday, January 13, 2010 2:00 PM - 3:00 PM EST

The upgrade from Oracle E-Business Suite (EBS) 11i to R12 is a unique opportunity to improve the security of your implementation by resolving existing security issues, configuring R12 securely, and taking advantage of new security features in R12.  This one hour education session will highlight R12 security changes and discuss a framework for a security focused R12 upgrade project.

Topics will include:

  • 11i and R12 differences and changes that impact security
  • R12 security enhancements and new features
  • Improving security throughout the R12 upgrade process

Click here to register for this webinar.