Friday, June 7, 2013

Password Decryption Risk for Oracle E-Business Suite

Password Decryption Risk for Oracle E-Business Suite

Unsecured passwords can allow a hacker to access application and database accounts by decrypting their passwords...

We had a great webinar in May in conjunction with Steve Kost of Integrigy.  We covered the risks related to the decryption of passwords.  Three questions for you:
  • Have you applied the new hash password scheme?  If you aren’t sure, read more about it in MOS Notes 457166.1 and 1084956.1).
  • Do you consider the column that hosts the password data in the FND_USER table as ‘sensitive data.’
  • Is your password length for the applications and database less than eight digits?

If you have answered ‘no’ to any of these questions, you need to see our recorded webinar based on the webinar titled “Account Password Decryption, Threat Explored.”  This webinar along with others we have done over the past few years can be accessed at: http://www.erpra.net/WebinarAccessForm.html