We’ve been providing Oracle E-Business Suite secure configuration guidelines or best practices in our published MOS Notes and guides for some time now. Our secure configuration deployment guidelines include the following recommendations:
- Stay current with patching

- Apply the latest quarterly Critical Patch Update (CPU) in a timely manner. CPU alerts and information is available here:
- Keep up-to-date on the latest Oracle E-Business Suite Release Update Packs (RUPs) and Updates for Oracle E-Business Suite Release 12.2 and 12.1. Often times the latest releases and RUPs include security fixes and new security features. Our latest upgrade recommendations are available here:
- Follow our Secure Configuration Guidelines
- Review and follow our published guidelines for Oracle E-Business Suite deployments:
- Review and follow our published guidelines for DMZ deployments:
- Oracle E-Business Suite Release 12.2 Configuration in a DMZ (Note 1375670.1
- Oracle E-Business Suite Release 12 Configuration in a DMZ (Note 380490.1)
- Use the utilities available to check and monitor your compliance with our published guidelines
- Secure Configuration Console for Oracle E-Business Suite Release 12.2 or Release 12.1.3
- Security Configuration and Auditing Scripts for Oracle E-Business Suite (Note 2069190.1)
- Security compliance checks available with the Application Management Pack
- Check and Deploy Secure Configuration for Oracle EBS 12.2 and 12.1
- Secure Oracle E-Business Suite 12.2 with Allowed JSPs/Resources
- Secure Oracle E-Business Suite 12.2 with Cookie Domain Scoping
- Frequently Asked Questions about EBS Security
- Critical Patch Update for October 2017 Now Available
References
