Oracle E-Business Suite Security, Java 7 and Auto-Update
Maintaining a secure Oracle E-Business Suite implementation requires constant vigilance. For the desktop clients accessing Oracle E-Business Suite, Integrigy recommends running the latest version of Java 7 SE. Java 7 is fully supported by Oracle with Public Updates through April 2015 and is patched with the latest security fixes. Most likely in late 2014 we anticipate that Oracle will have released and certified Java 8 with the Oracle E-Business Suite.
Most corporate environments utilize a standardized version of Java, tested and certified for corporate and mission critical applications. As such the Java auto-update functionality cannot be used to automatically upgrade Java on all desktops. These environments require new versions of Java to be periodically pushed to all desktops. For more information on how to push Java updates through software distribution see MOS Note 1439822.1. This note also describes how to download Java versions with the Java auto-update functionality disabled.
Keep in mind too that the version of Java used with the E-Business Suite should be obtained from My Oracle Support. Your Desktop support teams may or may not have Oracle support accounts.
Other points to keep in mind:
- To support Java 7, the Oracle E-Business Suite application servers must be updated per the instructions in MOS Note 393931.1
- “Non-Static Versioning” should be used the E-Business Suite to allow for later versions of the JRE Plug-in to be installed on the desktop client. For example, with Non-Static versioning JRE 7 will be invoked instead of JRE 6 if both are installed on a Windows desktop. With Non-Static versioning, the web server’s version of Java is the minimum version that can be used on the desktop client.
- You will need to implement the Enhanced JAR File signing for the later versions of Java 7 (refer to Integrigy blog posting for more information)
- Remember to remove all versions of Java that are no longer needed – for example JIinitiator
You may continue using Java 6. As an Oracle E-Business Suite customer, you are entitled to Java 6 updates through Extended Support. The latest Java 6 update (6u75) may be downloaded from My Oracle Support. This version (6u75) is equal to 7u55 for security fixes.
If you have questions, please contact us at firstname.lastname@example.org
- Oracle E-Business Suite Security - Signed JAR Files - What Should You Do
- All Java SE Downloads on MOS https://support.oracle.com/rs?type=doc&id=1439822.1
- Deploying JRE for Windows Clients in EBS R12 https://support.oracle.com/rs?type=doc&id=393931.1
- Static vs. Non-static Versioning and Set Up Options See Appendix B in https://support.oracle.com/rs?type=doc&id=393931.1