Oracle Security Evaluations

Oracle Security Evaluations are an integral part of the Oracle Software Security Assurance program. Go to Security Evaluations for more information on the evaluations and validations that Oracle undertake. 

Status of Oracle Security Evaluations 1

Common Criteria and FIPS Evaluations

Common Criteria

In Evaluation


 

Product Release Level Criteria Platform
Java Card Platform Implementation for Infineon on SLE 78 (SLJ 52GxxyyyzR)  1.0 EAL5+ Java Card Protection Profile Open Configuration Version 3.0 SLE78CLFX4000P(M) with the cryptographic library RSA - EC - SHA-2 – Toolbox (Platform. Certification ID: BSI-DSZ-CC-0782)
Oracle Communications Diameter Signaling Router  5.0   Protection Profile for Network Devices version 1.1  


Common Criteria Evaluated

Oracle Database

Oracle Servers

Oracle Fusion Middleware

Oracle Applications

Other

Oracle Database

Oracle Linux

Solaris

Oracle Application Server

Oracle AquaLogic

Oracle Business Intelligence

Oracle Enterprise Manager

Oracle Identity and Access Management

Oracle Identity Manager

Oracle Internet Directory

Oracle WebLogic

Oracle Primavera

Passlogix

Siebel


Oracle Database

Product Type Product Release Level Criteria Platform Status
Oracle Database Oracle Database 11g Release 2

 

Standard Edition (SE) & Standard Edition 1 (SE1)

11.2.0.2 EAL4+ US PP DMS for Basic Robustness  Environment

RedHat Enterprise Linux AS version 5

SuSE Linux Enterprise Server 10 SP1

Oracle Linux version 5 update 1

Evaluated

Oracle Database 11g Release 2

Enterprise Edition

11.2.0.2 EAL4+ US PP DMS for Basic Robustness  Environment

RedHat Enterprise Linux AS version 5

SuSE Linux Enterprise Server 10 SP1

Oracle Linux version 5 update 1

Evaluated
Oracle Database Vault 11g

 

11.1.0.7 EAL4+ US PP DMS for Basic Robustness  Environment

RedHat Enterprise Linux AS version 5

SuSE Linux Enterprise Server 10 SP1

Oracle Linux version 4 update 5

Evaluated

Oracle Database 11g

Standard Edition (SE) & Standard Edition 1 (SE1)

11.1.0.7 EAL4+ US PP DMS for Basic Robustness  Environment

RedHat Enterprise Linux AS version 5

SuSE Linux Enterprise Server 10 SP1

Oracle Linux version 4 update 5

Evaluated

Oracle Database 11g

Enterprise Edition

11.1.0.7 EAL4+ US PP DMS for Basic Robustness  Environment

RedHat Enterprise Linux AS version 5

SuSE Linux Enterprise Server 10 SP1

Oracle Linux version 4 update 5

Evaluated
Oracle Label Security 11g 11.1.0.7 EAL4+ US PP DMS for Basic Robustness  Environment

RedHat Enterprise Linux AS version 5

SuSE Linux Enterprise Server 10 SP1

Oracle Linux version 4 update 5

Evaluated

Oracle Database 10g

EE, SE and SE1 Editions

 

10.2.0.3 EAL4+ US PP DMS for Basic Robustness  Environment RedHat Enterprise Linux 4

SuSE Linux Enterprise Server 9
Evaluated
Oracle Label Security 10g 10.2.0.3 EAL4+ US PP DMS for Basic Robustness  Environment RedHat Enterprise Linux 4

SuSE Linux Enterprise Server 9


Evaluated
Oracle Database 10g 10.1.0.4.0 EAL4+ DBMS PP RedHat Enterprise Linux Evaluated
Oracle Label Security 10g 10.1.0.4.0 EAL4+ DBMS PP RedHat Enterprise Linux Evaluated
Oracle9i Database 9.2.0.1.0 EAL4+ DBMS PP Solaris 8, NT 4.0
SuSE SLES8
Evaluated
Oracle9i Label Security 9.2.0.1.0 EAL4+ DBMS PP Solaris 8, NT 4.0
SuSE SLES8
Evaluated
Oracle8i Label Security 8.1.7 EAL4 DBMS PP Solaris 8, NT 4.0
SuSE SLES8
Evaluated
Oracle8i Database 8.1.7 EAL4 DBMS PP Solaris 8 Evaluated
Oracle8 Database Server 8.0.5 EAL4 DBMS PP NT 4.0 Evaluated
Oracle7 Server 7.2.2.4.1.3 EAL4 C.DBMS PP NT 3.51 Evaluated
 


Oracle Servers

***
Product Type Product Release Level Criteria Platform Status
Oracle Linux Oracle Linux Version 5 Update 1 EAL4+ CAPP HP, DELL, OVM Evaluated
Oracle Linux Version 4 Update 4 & 5 EAL4+ CAPP HP, DELL Evaluated
Oracle Solaris Oracle Solaris Version 11.1 EAL4+ BSI OSPP Hardware Independent Evaluated
Oracle Solaris 10 11/06 Trusted Extensions EAL4+

CAPP, RBAC, LSPP

See Security Target Evaluated
Oracle Solaris 10 5/09 Trusted Extensions
Oracle Solaris 10 5/08 Trusted Extensions
Oracle Solaris 10 11/06 EAL4+

CAPP, RBAC

See Security Target Evaluated
Oracle Solaris 10 5/09
Oracle Solaris 10 5/08
Oracle Solaris 10 03/05 EAL4+ CAPP, RBAC See Security Target Evaluated
Oracle Solaris 9 08/03 EAL4+ CAPP, RBAC See Security Target Evaluated
Trusted Oracle Solaris 8 4/01 EAL4 CAPP, RBAC, LSPP See Security Target Evaluated
Oracle Solaris 8 02/02 EAL4 CAPP   Evaluated
Oracle Solaris 8 8 with AdminSuite v 3.0.1 EAL4 CAPP   Evaluated
 


Oracle Fusion Middleware

Product Type Product Release Level Criteria Platform Status
Oracle Application Server Oracle HTTP Server 10g 10.1.2 EAL4+

Solaris 8

Solaris 9

Evaluated
Oracle Application Server 10g 9.0.4.1.0 EAL4+
Solaris 8 Evaluated
AquaLogic AquaLogic Interaction Publisher 6.4 EAL2+

Windows Server 2003 SP1
Solaris 10
Red Hat Enterprise Linux 4 Update 3

Evaluated
AquaLogic Interaction Collaboration 4.2 EAL2+
Windows Server 2003 SP1
Solaris 10
Red Hat Enterprise Linux 4 Update 3
Evaluated
Oracle AquaLogic Business Process Management Suite Version 6.0 MP4 EAL2+

Windows Server 2003 SP1
Solaris 9 & 10 (on SPARC)
Red Hat Enterprise Linux 4.x (x86-32,x86-64,Itanium-64)

SuSE Linux Enterprise Server 10 (x86-32,x86-64,Itanium-64)

HP-UX 11.23 ( Itanium-64), AIX 5.3

Evaluated
AquaLogic Interaction 6.1 with AquaLogic Interaction Development Kit   EAL2+

Windows Server 2003 SP1
Solaris 10 (on SPARC)
Red Hat Enterprise Linux 4 Update 3 (x86)

Evaluated
Oracle Business Intelligence Oracle Business Intelligence Enterprise Edition Release 10.1.2 EAL3
Oracle Linux, Version 4 Update 5 Evaluated
Oracle Enterprise Manager Oracle Enterprise Manager 10g Grid Control Release 5 10.2.0.5 EAL4+
RedHat Enterprise Linux AS version 5

SuSE Linux Enterprise Server 10 SP1

 

Oracle Linux version 5

Evaluated
Oracle Identity and Access Manager Oracle Identity and Access Management 10g Release 3 (10.1.4.0.1) EAL4+
RedHat Enterprise Linux 4 Evaluated
Oracle Identity Manager Oracle Identity Manager 9.1.0 EAL4+
RedHat Enterprise Linux AS version 4 Update 5 Evaluated
Oracle Internet Directory Oracle Internet Directory 10g 10.1.4.0.1 EAL4+
RedHat Enterprise Linux 4 Evaluated
Oracle Internet Directory 10g 9.0.4.0.0 EAL4+
Solaris 8 Evaluated
WebLogic BEA WebLogic Server® 8.1 SP5 EAL2+
Java 2 BEA JRockit®1.4.2_08 SDK or
Sun Java 2 SDK 1.4.2_08 with Java HotSpot™ Client VM
Evaluated
BEA WebLogic Portal V8.1 SP5 with BEA06-81/02 and BEA07-107.02 security advisory patches EAL2+

Java 2 BEA JRockit®1.4.2_08 SDK or Sun Java 2 SDK 1.4.2_08 with Java HotSpot™ Client VM

 

Evaluated
BEA WebLogic Platform V8.1 SP6 with BEA07-169.00 Security Advisory Patch EAL2+
BEA JRockit®1.4.2_10 SDK or Sun Java 2 SDK 1.4.2_11 with Java HotSpot™Client VM Evaluated
BEA WebLogic Integration V8.1 SP6 with BEA07-169.00 Security Advisory Patch EAL2+
BEA JRockit®1.4.2_10 SDK or Sun Java 2 SDK 1.4.2_11 with Java HotSpot™Client VM Evaluated
BEA WebLogic Server V7.0 SP6 with BEA05-107.00 advisory patch EAL2+

Microsoft Windows 2000 Server
SP4 with Sun Java 2 SDK 1.3.1

 

Evaluated


Oracle Applications

Product Type Product Release Level Criteria Platform Status
Oracle Primavera Primavera P6 Enterprise Project Portfolio Management v6.2.1 EAL4
  Evaluated
 


Other Products

Product Type Product Release Level Criteria Platform Status
Passlogix Passlogix v-GO Access Accelerator Suite 6 EAL3+
MS Windows environment Evaluated
Siebel Siebel eBusiness 7.8.2 EAL2
Application Server: MS Windows 2000 Advanced Server SP4; Remote Workstation: MS Windows 2000 Professional SP4 Evaluated

 

Status of Oracle Security Evaluations 2

Regionally Specific Criteria (Obsolete) and Sponsored Evaluations

Scheme Product Release Level Criteria Platform Status
Common Criteria Red Hat Linux 3 AS ES WS EAL2
Sponsored by Oracle Evaluated
ITSEC Oracle7 Server 7.3.4.0.0 E3 / F-C2 E3 / F-C2 NT 4.0 Evaluated
Oracle7 Server 7.2.2.4.13 E3 / F-C2 E3 / F-C2 NT 3.51 Evaluated
Oracle7 Server 7.0.13.6 E3 / F-C2 E3 / F-C2 Solaris 2.2 Evaluated
Trusted Oracle7 7.2.3.0.4 E3 / F-B1 E3 / F-B1 HP-UX CMW 10.16 Evaluated
Trusted Oracle7 7.1.5.9.3 E3 / F-B1 E3 / F-B1 Trusted Solaris 1.2 Evaluated
Trusted Oracle7 7.0.13.6 E3 / F-B1 E3 / F-B1 Solaris CMW 1.0 Evaluated
Trusted Solaris 2.5.1 E3 / F-B1 E3 / F-B1   Evaluated
TCSEC Oracle7 Server 7.0.13.1 C2 C2 HP-UX BLS 8.0.4 Evaluated
Trusted Oracle7 7.0.13.1 B1 B1 HP-UX BLS 8.0.4 Evaluated
Russian Oracle8 Database 8.0.3 IV Russian HP-UX 10.20 Evaluated
Oracle7 Server 7.3.4 III Russian NT 4.0 Evaluated