01Overview
Oracle E-Business Suite is the financial and HR backbone of thousands of enterprises, yet its sprawling FND security model, thousands of responsibilities, and 25-year-old default accounts make it one of the hardest ERP platforms to audit. This tool tackles that head-on: two single-file Python scanners that run 140 security checks across 13 domains against a live R12.x instance or against offline CSV exports, then produce console, JSON, and self-contained HTML reports.
The dual-mode design is the differentiator. Security teams with direct database access run the live scanner (`oracle_ebs_scanner.py`, ~4,000 lines, one dependency: `oracledb`). Teams behind a locked-down DBA gate hand off a single SQL export script, get back a folder of CSVs, and run the zero-dependency offline scanner (`oracle_ebs_offline_scanner.py`, stdlib only) on any workstation. Both scanners are kept byte-for-byte in sync on rule IDs, severities, and the `Finding` contract, so the same audit is reproducible whether or not the auditor ever touches production.
Coverage spans the full EBS attack surface: default and terminated-user accounts, password and sign-on policy, profile options, responsibility sprawl, 20 segregation-of-duties conflict pairs across every major financial module, dangerous concurrent programs (FNDCPASS/FNDLOAD), AuditTrail configuration, Oracle Database hardening, patch/EOL posture, workflow health, application configuration, PII/data-privacy exposure, and custom PL/SQL code security. Every finding carries a severity, an issue explanation, a concrete remediation, and a CWE mapping (25 distinct CWEs).
It is built for SOX auditors, IT risk teams, and EBS administrators who need evidence, not guesswork. Findings map to SOX, CIS Oracle Database Benchmark, NIST 800-53, PCI-DSS v4.0, HIPAA, ISO 27001, and DISA STIG, and the scanner returns a non-zero exit code on any CRITICAL/HIGH finding so it can gate a CI/CD pipeline.
02Key Capabilities
Dual live + offline scanning
Audit a running EBS database directly via oracledb, or analyze CSV exports with a zero-dependency stdlib scanner when DBA access is restricted.
140 checks across 13 domains
Covers user access, passwords, profile options, responsibilities, SoD, concurrent programs, audit trail, DB hardening, patching, workflow, app config, data privacy, and custom code.
20 segregation-of-duties conflict pairs
Detects toxic responsibility combinations (AP/AR, GL/AP, PO/Receiving, HR/Payroll, Admin/GL, and more) across every major financial module.
Oracle Database hardening audit
Eighteen DB checks flag default accounts, PUBLIC EXECUTE on sensitive packages, DBA sprawl, O7_DICTIONARY_ACCESSIBILITY, network encryption, and Database Vault/FGA gaps.
Data privacy & PII exposure detection
Ten DPP checks find non-standard schemas with SELECT on HR and customer PII, unencrypted card data, SSN access, and unmasked non-production data.
Custom code security review
Ten CCS checks scan custom PL/SQL for SQL injection, hardcoded credentials, insecure FND_USER_PKG usage, security-table triggers, and AUTHID CURRENT_USER packages.
Read-only, safe by design
Requires only SELECT access; connect as APPS or a custom audit schema, and checks skip gracefully when optional views or CSVs are unavailable.
Self-contained HTML reports
Single-file HTML with a Catppuccin Mocha dark theme, severity/category filter dropdowns, full-text search, and expandable issue/fix detail per finding.
CWE-mapped, remediation-first findings
Every finding includes severity, context, a plain-language issue, a concrete fix, and one of 25 CWE identifiers for triage and reporting.
CI/CD-ready exit codes
Returns exit code 1 on any CRITICAL or HIGH finding and 0 otherwise, with a --severity floor so pipelines can gate on posture.
SQL export bridge for air-gapped audits
A single export_ebs_audit_data.sql produces ~45 CSVs that the offline scanner consumes, enabling audits without ever installing Python on the DB host.
Multi-framework compliance mapping
Maps findings to SOX, CIS Oracle DB Benchmark, NIST 800-53, PCI-DSS v4.0, HIPAA, ISO 27001, and DISA STIG.
03Architecture
Two self-contained, single-file Python scanners share one audit design and stay in lockstep on rule IDs and severities. A scan() orchestrator invokes 13 check-group methods; each emits Finding objects (slotted dataclass with rule_id, name, category, severity, source, context, description, recommendation, cwe). The live scanner sources data from Oracle via oracledb queries; the offline scanner loads the same data from CSVs produced by the SQL export script. Both feed the same trio of report writers (console, JSON, HTML).
04Project Structure
oracle_ebs_scanner.pyLive database scanner (v1.4.0, ~4,077 lines) requiring the oracledb driver.oracle_ebs_offline_scanner.pyZero-dependency offline CSV scanner (~3,526 lines), stdlib only, kept in sync with the live scanner.export_ebs_audit_data.sql~726-line SQL script that exports ~45 audit CSVs for offline analysis.test_data/Sample CSV exports plus generated report.html/report.json demonstrating offline output.README.mdFull documentation: check catalog, CLI reference, privileges, compliance and CWE mappings.CLAUDE.mdProject/architecture notes and the both-scanners-must-stay-in-sync development contract.banner.svgREADME banner graphic.LICENSEMIT License..gitignoreExcludes IDE files and secrets.05Security Controls
06Technology Stack
- Language
- Python 3.8+
- DB driver
- oracledb (live scanner only)
- Offline mode
- Python standard library only (zero dependencies)
- CLI
- argparse with env-var fallbacks (ORA_HOST/ORA_SERVICE/ORA_USER/ORA_PASSWORD)
- Data collection
- SQL*Plus / SQLcl export script producing ~45 CSVs
- Reporting
- Console (color), JSON, self-contained HTML (Catppuccin Mocha, inline CSS/JS)
- License
- MIT
- Packaging
- Two single-file scripts, no build/install step for offline mode
07Quick Start
$ pip install oracledb $ python oracle_ebs_scanner.py --host dbhost.example.com --port 1521 --service EBSPROD --user APPS $ python oracle_ebs_scanner.py --dsn "dbhost:1521/EBSPROD" --user APPS --json report.json --html report.html --severity MEDIUM $ sqlplus APPS/password@EBSPROD @export_ebs_audit_data.sql # DBA generates CSV exports $ python oracle_ebs_offline_scanner.py ./ebs_export/ --json report.json --html report.html --severity HIGH $ python oracle_ebs_offline_scanner.py ./ebs_export/ --ref-date 2025-01-15 # accurate age calculations
08Compliance & Frameworks
09Integrations & Outputs
Explore Oracle EBS Security Audit
Full source, documentation, and deployment guides live on GitHub.