A frequent topic of discussion after any security assessment or review by auditors is the setting of O7_DICTIONARY_ACCESSIBILITY in Oracle Applications. 07_DICTIONARY_ACCESSIBILITY is a database initialization parameter that controls access to objects in the SYS schema.  It was originally intended to help with migrations from Oracle7 to newer versions where access to data dictionary objects is limited by default. From a pure security perspective, 07_DICTIONARY_ACCESSIBILITY should always be set to FALSE and is a very common security recommendations for Oracle Databases in general.

The APPLSYSPUB account is used by Oracle Applications to initially connect to the database and establish a session.  This account normally should have limited privileges.  However, during our audits the permissions assigned to APPLSYSPUB and PUBLIC are often a security risk and need to be corrected.


