In Part VIII of this blog series, we discussed keeping your Oracle Database current by running a Long Term Database Release in Premier Support and applying applicable security updates.
In this article, we’ll look at another important area to consider as you prepare for the Next Gen Tech Stack: reviewing and implementing Oracle’s security recommendations for Oracle E-Business Suite
Review Oracle’s Security Guidelines

Following Oracle’s security recommendations is an important part of maintaining a the security of your Oracle E-Business Suite environment. While meeting these recommendations is not a mandatory prerequisite for updating to the Next Generation Technology Stack, Oracle recommends that you review your current security posture and make every effort to implement the applicable recommendations before your update or as part of your Next Generation Technology Stack update project.
The starting point for reviewing the latest EBS security guidelines, features, and recommendations is the
“What guidelines should I follow to secure my Oracle E-Business Suite environment?” in Section 1.1 General Guidelines in FAQ: Oracle E-Business Suite Security (MOS Article ID KA1033).
As part of your review, focus on the following area:
Keep Your Environment Current
Keep your Oracle E-Business Suite environment up-to-date with patching. Staying current provides access to the latest security fixes and security features delivered through EBS updates.
Review Oracle’s latest EBS update recommendations and incorporate applicable updates into your regular maintenance plans. For more information see: Quarterly EBS Update Recommendations.
Apply Security Updates Promptly
Apply applicable Critical Patch Updates (CPUs), Critical Security Patch Updates (CSPUs), and fixes for Security Alerts promptly.
Oracle releases CPUs quarterly, CSPUs monthly, and Security Alerts as needed. Establish a regular process to review the applicable security updates, test them, and deploy them to your EBS environments without delay. For more information see:
- Critical Patch Update Advisory
- Identifying the Latest Monthly and Quarterly Critical Patch Update for Oracle E-Business Suite Release 12 (MOS Article ID KA923)
Follow the Secure Configuration Guidelines
Start by running the Secure Configuration Console to assess your EBS environment against key secure configuration guidelines. Review the results and remediate the identified issues. For more information see: Oracle E-Business Suite Security Guide, Release 12.2 – Secure Configuration Console.
The Secure Configuration Console checks many of the recommended security configurations, but it does not replace a review of the complete secure configuration guidance. After reviewing the console results, review and implement the applicable recommendations documented in the Oracle E-Business Suite Security Guide, Release 12.2 – Secure Configuration.
Enable Recommended Security Features
Review and configure the following EBS security features which provide additional layers of protection for your EBS environment:
- Allowed Resources
- Allowed Resources Authorizations
- Allowed Redirects
- Cookie Domain Scoping
- Hashed Passwords
Use the Secure Configuration Console and the Oracle E-Business Suite Security Guide to review the recommended configuration for these features. Several of these configurations are also evaluated by the Secure Configuration Console.
What Can You Do Now?
You don’t need to wait for the Next Generation Technology Stack to begin this work. You can:
- Keep your EBS environment current with recommended updates.
- Apply applicable CPUs, CSPUs, and Security Alert fixes promptly.
- Run the Secure Configuration Console and remediate identified issues.
- Review the complete EBS secure configuration guidelines.
Completing as much of this work as possible now will strengthen the security posture of your EBS environment and reduce the security work remaining as part of your Next Generation Technology Stack update project.
What’s Next
In Part X, we’ll discuss another important readiness consideration: migrating deprecated products or features and technologies to the latest supported product features and technologies.
References
- FAQ: Oracle E-Business Suite Security (MOS Article ID KA1033)
- Identifying the Latest Monthly and Quarterly Critical Patch Update for Oracle E-Business Suite Release 12 (MOS Article ID KA923)
- Oracle E-Business Suite Release 12.2: Consolidated List of Oracle Database Patches and Technology Bug Fixes (MOS Article ID KA989)
- Oracle E-Business Suite Release 12.2: Consolidated List of Oracle Fusion Middleware Patches and Technology Bug Fixes (MOS Article ID KA988)
- Oracle E-Business Suite Security Guide, Release 12.2
Related Articles
- Quarterly EBS Update Recommendations
- Part I: Preparing for the Next Gen Tech Stack – Assess Your Readiness
- Part II: Preparing for the Next Gen Tech Stack – Update to Oracle E-Business Suite Release 12.2.7 or Later
- Part III: Preparing for the Next Gen Tech Stack – Migrate to Oracle Analytics Publisher
- Part IV: Preparing for the Next Gen Tech Stack – Move to Oracle Linux 8 or RHEL 8
- Part V: Preparing for the Next Gen Tech Stack – Choose Your Path to Oracle Linux 8 or RHEL 8
- Part VI: Preparing for the Next Gen Tech Stack – Update to R12.ATG.PF.C.Delta.14
- Part VII: Preparing for the Next Gen Tech Stack – Complete the EBS System Schema Migration
- Prepare EBS 12.2 for the Next Gen Tech Stack
- Introducing the EBS Next Gen Tech Stack Readiness Checker
- Blog Series Summary: EBS 12.2 Application Technology Stack Update – Terminology and Concepts
