OBIEE Security: Catalogs, Access Control Lists and Permission Reports
The presentation catalog (Web Catalog) stores the content that users create within OBIEE. While the Catalog uses the presentation layer objects, do not confuse the presentation layer within the RPD with the presentation catalog. The presentation...OBIEE Security: Usage Tracking, Logging and Auditing for SYSLOG or Splunk
Enabling OBIEE Usage Tracking and Logging is a key part of most any security strategy. More information on these topics can be found in the whitepaper references below. It is very easy to setup logging such that a centralized logging solution such...OpenSSL Heartbleed (CVE-2014-0160) and Oracle E-Business Suite Impact
Integrigy has completed an in-depth security analysis of the "Heartbleed" vulnerability in OpenSSL (CVE-2014-0160) and the impact on Oracle E-Business Suite 11i (11.5) and R12 (12.0, 12.1, and 12.2) environments. The key issue is where in the...Integrigy Collaborate 2014 Presentations
Integrigy had a great time at Collaborate 2014 last week in Las Vegas. What did not stay in Las Vegas were many great sessions and a lot of good information on Oracle E-Business Suite 12.2, Oracle Security, and OBIEE. Posted below are...OBIEE Security: Repositories and Three Layers of Security
This blog series reviewing OBIEE security has to this point identified how users are defined and authenticated within WebLogic, the major security concerns with WebLogic and how application roles are defined and mapped to LDAP groups within...OBIEE Security: Repositories and RPD File Security
The OBIEE repository database, known as a RPD file because of its file extension, defines the entire OBIEE application. It contains all the metadata, security rules, database connection information and SQL used by an OBIEE application. The RPD file...Come See Integrigy at Collaborate 2014
Come see Integrigy’s sessions at Collaborate 2014 in Las Vegas (http://collaborate14.com/). Integrigy is presenting the following papers:IOUG - #526 Oracle Security Vulnerabilities Dissected, Wednesday, April 9, 11:00amOAUG – #14365 New Security...OBIEE Security: User Authentication, WebLogic, OPSS, Application Roles and LDAP
Where and how are OBIEE users authenticated? A few options exists. A later blog post will review how to use the Oracle E-Business Suite to authenticate user connections and pass the E-Business Suite session cookie to OBIEE. Many if not most OBIEE...OBIEE Security and WebLogic Scripting Tool (WLST)
Continuing our blog series on OBIEE security, when discussing WebLogic security, the WebLogic Scripting Tool (WLST) needs to understood. From a security risk perspective, consider WLST analogous to how DBAs use SQL to manage an Oracle database. Who...OBIEE Security Examined: WebLogic Security
As the first post in Integrigy’s blog series on OBIEE security, it makes sense to first look at WebLogic. As a Fusion Middleware 11g product, OBIEE 11g uses Oracle WebLogic for centralized common services, including a common security model. WebLogic...Oracle Business Intelligence Enterprise Edition (OBIEE) Security Examined
Oracle’s Business Intelligence Enterprise Edition (OBIEE) 11g is a powerful tool for accessing data, however this power means OBIEE security is imperative in order to protect the data. Throughout March and April 2014 Integrigy will be focusing our...Oracle E-Business Suite Logging and Auditing: Page Access Tracking
Sign-On Audit only logs professional forms activity – it does not log Oracle Applications Framework (OAF) user activity. Page Access Tracking is required to log OAF activity. Once enabled, the level of logging needs to be set as well as...Oracle E-Business Logging and Auditing: PCI, SOX, HIPAA, 27001 and FISMA
Continuing this blog series on Oracle E-Business logging and auditing, Integrigy’s log and audit framework is based on our consulting experience. We have also based it on compliance and security standards such as Payment Card Industry (PCI-DSS),...Oracle E-Business Logging and Auditing, CMM and SIEM
Most Oracle E-Business Suite implementations do not fully take advantage of the auditing and logging features. These features are sophisticated and are able to satisfy most organization’s compliance and security requirements. The default Oracle...Oracle E-Business Suite PCI DSS Compliance, Requirement 3.4 and Decryption Risk
PCI requirement 3.4 requires PAN data to be unreadable anywhere it is stored unless it is protected. With Release 12 credit cardholder data can be decrypted at any time as easily as it is encrypted by simply running the request set “Decrypt...
