Oracle EBS Security Audit

SaaS / SSPMv1.0.0

Live DB + offline CSV security audit for Oracle E-Business Suite R12.x with 68 checks across 10 domains, SoD detection, and 17+ CWE mappings

68
checks
10
categories
17+
cwes
4
loc

01Overview

Oracle E-Business Suite is the financial and HR backbone of thousands of enterprises, yet its sprawling FND security model, thousands of responsibilities, and 25-year-old default accounts make it one of the hardest ERP platforms to audit. This tool tackles that head-on: two single-file Python scanners that run 140 security checks across 13 domains against a live R12.x instance or against offline CSV exports, then produce console, JSON, and self-contained HTML reports.

The dual-mode design is the differentiator. Security teams with direct database access run the live scanner (`oracle_ebs_scanner.py`, ~4,000 lines, one dependency: `oracledb`). Teams behind a locked-down DBA gate hand off a single SQL export script, get back a folder of CSVs, and run the zero-dependency offline scanner (`oracle_ebs_offline_scanner.py`, stdlib only) on any workstation. Both scanners are kept byte-for-byte in sync on rule IDs, severities, and the `Finding` contract, so the same audit is reproducible whether or not the auditor ever touches production.

Coverage spans the full EBS attack surface: default and terminated-user accounts, password and sign-on policy, profile options, responsibility sprawl, 20 segregation-of-duties conflict pairs across every major financial module, dangerous concurrent programs (FNDCPASS/FNDLOAD), AuditTrail configuration, Oracle Database hardening, patch/EOL posture, workflow health, application configuration, PII/data-privacy exposure, and custom PL/SQL code security. Every finding carries a severity, an issue explanation, a concrete remediation, and a CWE mapping (25 distinct CWEs).

It is built for SOX auditors, IT risk teams, and EBS administrators who need evidence, not guesswork. Findings map to SOX, CIS Oracle Database Benchmark, NIST 800-53, PCI-DSS v4.0, HIPAA, ISO 27001, and DISA STIG, and the scanner returns a non-zero exit code on any CRITICAL/HIGH finding so it can gate a CI/CD pipeline.

02Key Capabilities

Dual live + offline scanning

Audit a running EBS database directly via oracledb, or analyze CSV exports with a zero-dependency stdlib scanner when DBA access is restricted.

140 checks across 13 domains

Covers user access, passwords, profile options, responsibilities, SoD, concurrent programs, audit trail, DB hardening, patching, workflow, app config, data privacy, and custom code.

20 segregation-of-duties conflict pairs

Detects toxic responsibility combinations (AP/AR, GL/AP, PO/Receiving, HR/Payroll, Admin/GL, and more) across every major financial module.

Oracle Database hardening audit

Eighteen DB checks flag default accounts, PUBLIC EXECUTE on sensitive packages, DBA sprawl, O7_DICTIONARY_ACCESSIBILITY, network encryption, and Database Vault/FGA gaps.

Data privacy & PII exposure detection

Ten DPP checks find non-standard schemas with SELECT on HR and customer PII, unencrypted card data, SSN access, and unmasked non-production data.

Custom code security review

Ten CCS checks scan custom PL/SQL for SQL injection, hardcoded credentials, insecure FND_USER_PKG usage, security-table triggers, and AUTHID CURRENT_USER packages.

Read-only, safe by design

Requires only SELECT access; connect as APPS or a custom audit schema, and checks skip gracefully when optional views or CSVs are unavailable.

Self-contained HTML reports

Single-file HTML with a Catppuccin Mocha dark theme, severity/category filter dropdowns, full-text search, and expandable issue/fix detail per finding.

CWE-mapped, remediation-first findings

Every finding includes severity, context, a plain-language issue, a concrete fix, and one of 25 CWE identifiers for triage and reporting.

CI/CD-ready exit codes

Returns exit code 1 on any CRITICAL or HIGH finding and 0 otherwise, with a --severity floor so pipelines can gate on posture.

SQL export bridge for air-gapped audits

A single export_ebs_audit_data.sql produces ~45 CSVs that the offline scanner consumes, enabling audits without ever installing Python on the DB host.

Multi-framework compliance mapping

Maps findings to SOX, CIS Oracle DB Benchmark, NIST 800-53, PCI-DSS v4.0, HIPAA, ISO 27001, and DISA STIG.

03Architecture

Two self-contained, single-file Python scanners share one audit design and stay in lockstep on rule IDs and severities. A scan() orchestrator invokes 13 check-group methods; each emits Finding objects (slotted dataclass with rule_id, name, category, severity, source, context, description, recommendation, cwe). The live scanner sources data from Oracle via oracledb queries; the offline scanner loads the same data from CSVs produced by the SQL export script. Both feed the same trio of report writers (console, JSON, HTML).

1
Live DB scanner (oracle_ebs_scanner.py)
~4,000-line OracleEBSScanner connects via oracledb and runs all checks against a live R12.x instance using read-only SELECT queries.
2
Offline CSV scanner (oracle_ebs_offline_scanner.py)
~3,500-line stdlib-only OracleEBSOfflineScanner that loads ~45 CSVs via _load_csv/load_data and runs the identical 140-check set with no dependencies.
3
SQL export bridge (export_ebs_audit_data.sql)
~726-line script of export queries a DBA runs to emit the CSV set the offline scanner consumes, decoupling data collection from analysis.
4
Check-group engine
A scan() orchestrator dispatches 13 domain methods (_check_users, _check_sod, _check_database, _check_data_privacy, _check_custom_code, etc.), each producing Finding records.
5
Finding model
A __slots__ dataclass carrying rule_id, severity, source, context, description, recommendation, and CWE, serialized uniformly across all outputs.
6
Report writers
print_report (color console), save_json (machine-readable), and save_html (filterable, searchable, self-contained Catppuccin-themed report).

04Project Structure

oracle_ebs_scanner.pyLive database scanner (v1.4.0, ~4,077 lines) requiring the oracledb driver.
oracle_ebs_offline_scanner.pyZero-dependency offline CSV scanner (~3,526 lines), stdlib only, kept in sync with the live scanner.
export_ebs_audit_data.sql~726-line SQL script that exports ~45 audit CSVs for offline analysis.
test_data/Sample CSV exports plus generated report.html/report.json demonstrating offline output.
README.mdFull documentation: check catalog, CLI reference, privileges, compliance and CWE mappings.
CLAUDE.mdProject/architecture notes and the both-scanners-must-stay-in-sync development contract.
banner.svgREADME banner graphic.
LICENSEMIT License.
.gitignoreExcludes IDE files and secrets.

05Security Controls

User account security (15 checks)
Flags active default/seeded accounts, terminated employees with live logins, orphan/shared/generic accounts, weak password hashes, direct APPS-schema login, and SysAdmins holding financial responsibilities.
Password & authentication (6 checks)
Verifies failed-login limit, minimum length >=8, hard-to-guess complexity, password history/no-reuse, and password age against SIGNON_* profile options.
Segregation of Duties (20 pairs)
Detects toxic responsibility combinations across AP, AR, GL, PO, INV, HR, Payroll, Cash Management, Fixed Assets, and System Administrator, each with a described business risk.
Database hardening (18 checks)
Checks locked default accounts, PUBLIC EXECUTE on UTL_FILE/DBMS_*, DBA grants to non-system schemas, UTL_FILE_DIR, remote OS auth, O7_DICTIONARY_ACCESSIBILITY, SQLNET encryption, Database Vault, and FGA policies.
Audit trail (12 checks)
Confirms EBS AuditTrail activation, audit coverage on 13 critical tables (FND_USER, AP/GL/PO transaction tables), DB audit_trail parameter, unified audit policies, and change auditing on profiles/responsibilities.
Concurrent programs (10 checks)
Finds dangerous programs (FNDCPASS, FNDLOAD, WFLOAD, CONCSUB) in non-admin request groups, host/OS-execution programs, and overly broad ALL-program request groups.
Profile options (10 checks)
Audits ICX_SESSION_TIMEOUT, non-HTTPS APPS_SERVLET_AGENT/APPS_FRAMEWORK_AGENT, FND_DIAGNOSTICS, guest password defaults, and sign-on audit level.
Data privacy & PII (10 checks)
Surfaces non-standard schemas with SELECT on HR (PER_ALL_PEOPLE_F) and customer (HZ_PARTIES) PII, unencrypted credit-card data, SSN access, non-production masking gaps, and PII data-extract interfaces.
Custom code security (10 checks)
Reviews custom PL/SQL for dynamic-SQL injection, hardcoded credentials, insecure FND_USER_PKG usage, triggers on security tables, security-config FNDLOAD scripts, and AUTHID CURRENT_USER packages.
Application config, patching & workflow (23 checks)
Validates document sequencing (SOX), approval limits, GL period control, Multi-Org security, EBS/DB EOL and patch recency, and workflow mailer/background-engine health.

06Technology Stack

Language
Python 3.8+
DB driver
oracledb (live scanner only)
Offline mode
Python standard library only (zero dependencies)
CLI
argparse with env-var fallbacks (ORA_HOST/ORA_SERVICE/ORA_USER/ORA_PASSWORD)
Data collection
SQL*Plus / SQLcl export script producing ~45 CSVs
Reporting
Console (color), JSON, self-contained HTML (Catppuccin Mocha, inline CSS/JS)
License
MIT
Packaging
Two single-file scripts, no build/install step for offline mode

07Quick Start

$ pip install oracledb
$ python oracle_ebs_scanner.py --host dbhost.example.com --port 1521 --service EBSPROD --user APPS
$ python oracle_ebs_scanner.py --dsn "dbhost:1521/EBSPROD" --user APPS --json report.json --html report.html --severity MEDIUM
$ sqlplus APPS/password@EBSPROD @export_ebs_audit_data.sql   # DBA generates CSV exports
$ python oracle_ebs_offline_scanner.py ./ebs_export/ --json report.json --html report.html --severity HIGH
$ python oracle_ebs_offline_scanner.py ./ebs_export/ --ref-date 2025-01-15   # accurate age calculations

08Compliance & Frameworks

SOX (Sarbanes-Oxley)
SoD controls (20 pairs), document sequencing, approval limits, audit trail, and period controls.
CIS Oracle Database Benchmark
DB hardening, password policies, PUBLIC privileges, audit config, and network encryption.
NIST 800-53
Access Control (AC), Audit (AU), Identification & Authentication (IA), Config Mgmt (CM), System/Comms (SC).
PCI-DSS v4.0
Req 2 (no defaults), Req 7 (access control), Req 8 (authentication), Req 10 (audit logging).
HIPAA / ISO 27001
Access controls, audit controls, and person authentication (HIPAA); A.9/A.12/A.18 (ISO 27001).
DISA STIG
DB parameters, audit configuration, authentication controls, and encryption.

09Integrations & Outputs

oracledb live database connection (Easy Connect or DSN)SQL export script producing ~45 CSV files for offline analysisJSON report export for SIEM/GRC ingestionSelf-contained HTML report (filterable, searchable)CI/CD gating via exit codes (1 on CRITICAL/HIGH) and --severity thresholdEnvironment-variable configuration for pipeline secrets

Explore Oracle EBS Security Audit

Full source, documentation, and deployment guides live on GitHub.