Showing posts with label gdemonte. Show all posts
Showing posts with label gdemonte. Show all posts

Thursday, July 6, 2017

Protecting Oracle E-Business Suite: Password Policy: Reducing the Attack Surface

This is the fourth consecutive blog post in our series on how to make Oracle E-Business Suite more secure. In this post, we will focus on reducing the attack surface - something that is a critical component for any successful information security strat...

from Protecting Oracle E-Business Suite: Password Policy: Reducing the Attack Surface

Thursday, June 29, 2017

Protecting Oracle E-Business Suite: Password Policy

For a third week in a row, we’re providing you with best practices for securing your Oracle E-Business Suite implementation. Today, we are going to talk about a common topic: password security. When it comes to password policy, the first thing that probably comes to mind is having a secure password. That is why in addition to all network security layers, it is very important to have a proper password policy, along with a users list and groups so to follow a guideline of how passwords are formed.

Oracle, Oracle EBS, Oracle E-Business Suite, Oracle EBS SecurityResearchSebastian Bortnik
06/29/2017


from Protecting Oracle E-Business Suite: Password Policy

Friday, June 23, 2017

Protecting Oracle E-Business Suite: Hashed Passwords

Last week, we begin a blogpost series with the objective of reviewing Oracle E-Business Suite Security. The first publication detailed how to activate the Server Security Feature, and in today’s post we will focus on password hashing. We will analyze the different types of hashing and how it is implemented in Oracle E-Business Suite.

ResearchMatias Mevied
06/23/2017


from Protecting Oracle E-Business Suite: Hashed Passwords

Thursday, June 15, 2017

Protecting Oracle E-Business Suite: Activate Server Security

As most of our regular readers may know, the Onapsis Research Labs have been working on developing Oracle Security for several months. We’ve done this by updating our readers with analysis on quarterly patch updates, and to date have released over one hundred advisories for this platform. In our continous goal to provide the industry with greater resources to secure their business critical applications, starting today we will be publishing a series of weekly blog posts focusing on different areas of protecting Oracle E-Business Suite.

Oracle, Oracle EBS, Oracle E-Business SuiteResearchSebastian Bortnik
06/15/2017


from Protecting Oracle E-Business Suite: Activate Server Security

Thursday, April 13, 2017

How the Proposed OWASP TOP 10 Changes Would Affect SAP and Oracle

While only in release candidate form, the current proposed changes to the OWASP Top 10 Application Security Risks provide clear guidance for any enterprise that needs to secure and protect their critical enterprise business applications. In general, th...

from How the Proposed OWASP TOP 10 Changes Would Affect SAP and Oracle

Changes to the OWASP Top 10 Release Candidate

While only in release candidate form, the current proposed changes to the OWASP Top 10 Application Security Risks provide clear guidance for any enterprise that needs to secure and protect their critical enterprise business applications. In general, th...

from Changes to the OWASP Top 10 Release Candidate

Friday, April 7, 2017

SAP Notes March Review: FAQ about High Priority Notes

We are just a few days away from the release of SAP’s April Security Notes. Since this past month included some of the most critical notes we have seen to date for SAP, we’d like to review a few things we saw in March to ensure we have everything fully covered before heading into April. It was an interesting month for SAP Security, as findings from our Researchers yielded the second ‘Hot News’ note to date for 2017. In addition however, there were some other important vulnerabilities published in March that were tagged as ‘High Priority’ and should be mitigated if present in SAP systems.

SAP Security NotesSebastian Bortnik
04/07/2017


from SAP Notes March Review: FAQ about High Priority Notes

Friday, January 6, 2017

SAP Security Notes 2016: A Year in Review

Since its foundation, the Onapsis Research Labs have been actively helping SAP improve its security by researching and reporting system vulnerabilities. On the second Tuesday of each month, the Onapsis Research Labs publishes a detailed analysis of the...

from SAP Security Notes 2016: A Year in Review

SAP Security Notes 2016: A Year in Review

Since its foundation, the Onapsis Research Labs have been actively helping SAP improve its security by researching and reporting system vulnerabilities. On the second Tuesday of each month, the Onapsis Research Labs publishes a detailed analysis of the...

from SAP Security Notes 2016: A Year in Review

Wednesday, October 19, 2016

Oracle Publishes 253 New Vulnerabilities in October 2016 CPU

Yesterday, Oracle released its quarterly Critical Patch Update (CPU) to provide customers with detailed information about the latest vulnerabilities affecting Oracle business critical applications. This post will help Oracle customers better understand...

from Oracle Publishes 253 New Vulnerabilities in October 2016 CPU

Oracle Publishes 253 New Vulnerabilities in October 2016 CPU

Yesterday, Oracle released its quarterly Critical Patch Update (CPU) to provide customers with detailed information about the latest vulnerabilities affecting Oracle business critical applications. This post will help Oracle customers better understand...

from Oracle Publishes 253 New Vulnerabilities in October 2016 CPU