Thursday, July 6, 2017
Protecting Oracle E-Business Suite: Password Policy: Reducing the Attack Surface
from Protecting Oracle E-Business Suite: Password Policy: Reducing the Attack Surface
Thursday, June 29, 2017
Protecting Oracle E-Business Suite: Password Policy
For a third week in a row, we’re providing you with best practices for securing your Oracle E-Business Suite implementation. Today, we are going to talk about a common topic: password security. When it comes to password policy, the first thing that probably comes to mind is having a secure password. That is why in addition to all network security layers, it is very important to have a proper password policy, along with a users list and groups so to follow a guideline of how passwords are formed.
from Protecting Oracle E-Business Suite: Password Policy
Friday, June 23, 2017
Protecting Oracle E-Business Suite: Hashed Passwords
Last week, we begin a blogpost series with the objective of reviewing Oracle E-Business Suite Security. The first publication detailed how to activate the Server Security Feature, and in today’s post we will focus on password hashing. We will analyze the different types of hashing and how it is implemented in Oracle E-Business Suite.
from Protecting Oracle E-Business Suite: Hashed Passwords
Thursday, June 15, 2017
Protecting Oracle E-Business Suite: Activate Server Security
As most of our regular readers may know, the Onapsis Research Labs have been working on developing Oracle Security for several months. We’ve done this by updating our readers with analysis on quarterly patch updates, and to date have released over one hundred advisories for this platform. In our continous goal to provide the industry with greater resources to secure their business critical applications, starting today we will be publishing a series of weekly blog posts focusing on different areas of protecting Oracle E-Business Suite.
from Protecting Oracle E-Business Suite: Activate Server Security
Thursday, April 13, 2017
How the Proposed OWASP TOP 10 Changes Would Affect SAP and Oracle
from How the Proposed OWASP TOP 10 Changes Would Affect SAP and Oracle
Changes to the OWASP Top 10 Release Candidate
from Changes to the OWASP Top 10 Release Candidate
Friday, April 7, 2017
SAP Notes March Review: FAQ about High Priority Notes
We are just a few days away from the release of SAP’s April Security Notes. Since this past month included some of the most critical notes we have seen to date for SAP, we’d like to review a few things we saw in March to ensure we have everything fully covered before heading into April. It was an interesting month for SAP Security, as findings from our Researchers yielded the second ‘Hot News’ note to date for 2017. In addition however, there were some other important vulnerabilities published in March that were tagged as ‘High Priority’ and should be mitigated if present in SAP systems.
from SAP Notes March Review: FAQ about High Priority Notes
Friday, January 6, 2017
SAP Security Notes 2016: A Year in Review
from SAP Security Notes 2016: A Year in Review
SAP Security Notes 2016: A Year in Review
from SAP Security Notes 2016: A Year in Review
Wednesday, October 19, 2016
Oracle Publishes 253 New Vulnerabilities in October 2016 CPU
from Oracle Publishes 253 New Vulnerabilities in October 2016 CPU
Oracle Publishes 253 New Vulnerabilities in October 2016 CPU
from Oracle Publishes 253 New Vulnerabilities in October 2016 CPU