Oracle Critical Patch Update, July 2024 Security Update Review | Qualys Security Blog (2024)

Oracle released its third quarterly edition of Critical Patch Update, which contains patches for 386 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.

In the third quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 95, constituting about 24% of the total patches released.Oracle Financial Services Applications and Oracle Fusion Middlewarefollowed, with 60 and 41security patches, respectively.

319 of the 386, i.e., about 83% of security patches, are for non-Oracle CVEs, which are security fixes for issues in third-party products such as open-source components included and exploitable in the context of their Oracle product distributions.

This month’s batch of security patches contains 15 updates for Oracle Database products. Product-wise distribution is as follows:

  • 8 new security updates for Oracle Database Server with a maximum reported CVSS Base Score of 7.5.
    • 1 of these updates applies to client-only deployments of the Oracle Database.
  • 1 new security update for Oracle Application Express with a maximum reported CVSS Base Score of 4.7.
  • 2 new security updates for Oracle Essbase with a maximum reported CVSS Base Score of 6.7.
  • 1 new security update for Oracle GoldenGate with a maximum reported CVSS Base Score of 5.9.
  • 1 new security update for Oracle NoSQL Database with a maximum reported CVSS Base Score of 5.9.
  • 1 new security update for Oracle REST Data Services with a maximum reported CVSS Base Score of 5.3.
  • 1 new security update for Oracle TimesTen In-Memory Database with a maximum reported CVSS Base Score of 4.3.

In these security updates, Oracle has covered product families, including Oracle Database Server, Oracle Application Express, Oracle Essbase, Oracle GoldenGate, Oracle NoSQL Database, Oracle REST Data Services, Oracle TimesTen In-Memory Database, Oracle Commerce, Oracle Communications Applications, Oracle Communications, Oracle Construction and Engineering, Oracle E-Business Suite, Oracle Enterprise Manager, Oracle Financial Services Applications, Oracle Fusion Middleware, Oracle Analytics, Oracle HealthCare Applications, Oracle Hyperion, Oracle Insurance Applications, Oracle Java SE, Oracle JD Edwards, Oracle MySQL, Oracle PeopleSoft, Oracle Retail Applications, Oracle Siebel CRM, Oracle Supply Chain, Oracle Systems, Oracle Utilities Applications, Oracle Virtualization.

Qualys QID Coverage

Qualys has released 12 QIDs mentioned in the table below:

QIDsTitle
20438Oracle MySQL JULY 2024 Critical Patch Update (CPUJUL2024)(CVE-2024-21185)
380193Oracle Managed Virtualization (VM) VirtualBox Denial of Service (DoS) Vulnerability (CPUJUL2024) (CVE-2024-21161)
380192Oracle Managed Virtualization (VM) VirtualBox Multiple Vulnerabilities (CPUJUL2024) (CVE-2024-21141, CVE-2024-21164)
380191Oracle Coherence April 2024 Critical Patch Update (CPUJUL2024)
20437Oracle MySQL JULY 2024 Critical Patch Update (CPUJUL2024)
380190Oracle Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (CPUJUL2024)
296114Oracle Solaris 11.4 Support Repository Update (SRU) 71.170.2 Missing (CPUJUL2024)
87557Oracle WebLogic Server Multiple Vulnerabilities (CPUJUL2024)
380188Oracle Java Standard Edition (SE) Critical Patch Update – July 2024 (CPUJUL2024)
20436Oracle Database 21c Critical Patch Update – July 2024
20435Oracle Database 19c Critical OJVM Patch Update – July 2024
20420Oracle Database 19c Critical Patch Update – July 2024
152029Oracle WebLogic Server Multiple Vulnerabilities (CPUJUL2024)

Note: The table will be updated with the additional QIDs once released.

Notable Oracle Vulnerabilities Patched

Oracle Communications

This Critical Patch Update for Oracle Communications contains 95 security patches. Out of these, 84vulnerabilities can be exploited over a network without user credentials.

CVE-2024-23897, CVE-2023-37920, and CVE-2022-48174 in different Oracle Communications products have critical severity ratings and CVSS scores of 9.8. A remote attacker may exploit these vulnerabilities in a low-complexity network attack.

Oracle Financial Services Applications

This Critical Patch Update for Oracle Financial Services Applications contains 60 new security patches. 44of these vulnerabilities can be remotely exploitable without authentication.

CVE-2023-47248 and CVE-2022-36944in different Oracle Financial Services Applications products have critical severity ratings and CVSS scores of 9.8. A remote attacker may exploit these vulnerabilities in a low-complexity network attack.

Oracle Fusion Middleware

This Critical Patch Update for Oracle Fusion Middleware contains 41 new security patches. 32 of these vulnerabilities can be remotely exploitable without authentication.

CVE-2023-45853, CVE-2022-45378, CVE-2023-34034, andCVE-2024-21181in different Oracle Communications products have critical severity ratings and CVSS scores of 9.8. A remote attacker may exploit these vulnerabilities in a low-complexity network attack.

Oracle MySQL

This Critical Patch Update for Oracle MySQL contains 37 security patches. 11 of these vulnerabilities may be remotely exploitable without authentication.

CVE-2023-37920 in the MySQL Cluster has a critical severity rating and CVSS score of 9.8. A remote attacker may exploit these vulnerabilities in a low-complexity network attack.

Oracle Communications Applications

This Critical Patch Update for Oracle Communications Applications contains 20 security patches. 14 of these vulnerabilities may be exploited over a network without requiring user credentials.

CVE-2022-34381in theOracle Communications Billing and Revenue Managementhas a critical severity rating and CVSS score of 9.8. A remote attacker may exploit these vulnerabilities in a low-complexity network attack.

Oracle Analytics

This Critical Patch Update forOracle Analyticscontains 17 security patches. 12 of these vulnerabilities may be exploited over a network without requiring user credentials.

CVE-2022-0239 and CVE-2022-21797in theOracle Business Intelligence Enterprise Editionhave critical severity ratings and CVSS scores of 9.8. A remote attacker may exploit these vulnerabilities in a low-complexity network attack.

Oracle Siebel CRM

This Critical Patch Update forOracle Analyticscontains 12 security patches. 11 of these vulnerabilities may be exploited over a network without requiring user credentials.

CVE-2022-37434in theSiebel CRM Deploymenthas a critical severity rating and CVSS score of 9.8. A remote attacker may exploit these vulnerabilities in a low-complexity network attack.

Related

Oracle Critical Patch Update, July 2024 Security Update Review | Qualys Security Blog (2024)

FAQs

What is Oracle Critical Patch Update Advisory? ›

A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products.

Are Oracle critical Patch updates cumulative? ›

These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical Patch Update Advisory. Thus, prior Critical Patch Update advisories should be reviewed for information regarding earlier published security patches.

Where can I download the Oracle Critical Patch Update? ›

Downloading and Installing Patch Updates
  • Log in to My Oracle Support. ...
  • On the main My Oracle Support page, click Patches and Updates tab.
  • In the Patch Search group, select Product or Family (Advanced).
  • In the Product field, select Oracle Database.
  • In the Release field select the release number. ...
  • Click Search.

What is a critical security update? ›

As the name suggests, Microsoft's "critical" Windows updates are more than just updates to keep your system running efficiently. Critical updates also plug up security holes that Microsoft has detected in its operating systems. Failing to plug these holes can leave your computer vulnerable to hackers and viruses.

What are two important reasons to upgrade and patch Oracle? ›

Here are the top 10 reasons why you should consider it.
  • Support. If you pay for an Oracle support contract, only Oracle 12.1. ...
  • Updated hardware and operating systems. ...
  • Security patches. ...
  • Reduced labor. ...
  • Marketplace relevance. ...
  • Easier future upgrades. ...
  • Data protection. ...
  • Database consolidation.
Jan 23, 2017

How to check patch update in Oracle? ›

Determine Current Patch Levels
  1. Display a command window and navigate to the location of the OPatch executable: ORACLE_HOME/OPatch.
  2. Run the lsinventory utility using the following command syntax: ...
  3. To run the lsinventory utility against other Oracle homes, repeat the previous steps for each Oracle home.

Does cumulative update include security updates? ›

Monthly security update releases are cumulative. The release includes both new and previously released security fixes, along with nonsecurity content introduced in the prior month's Optional nonsecurity preview release.

What is an Oracle security patch? ›

The patches address significant security vulnerabilities and also include code fixes that are prerequisites for the security fixes. The security updates for all products which receive CPUs are available to active Oracle Support customers on My Oracle Support.

What is Oracle patch set update? ›

Patch Set Updates (PSU) are the same cumulative updates which include both security fixes and priority fixes. The key with PSUs is that they are minor version upgrades (e.g. 11.2. 0.1. 1 to 11.2.

What are the patches for July 2024? ›

Microsoft Patches for July 2024

This month, Microsoft released a gargantuan 139 new CVEs in Windows and Windows Components; Office and Office Components; . NET and Visual Studio; Azure; Defender for IoT; SQL Server; Windows Hyper-V; Bitlocker and Secure(?) Boot; Remote Desktop; and Xbox (yes Xbox!).

How to install Oracle security patches? ›

On the main My Oracle Support page, click Patches & Updates. In the Patch Search region, select Product or Family (Advanced). On the Product or Family (Advanced) display, provide information about the product, release, and platform for which you want to obtain patches, and click Search.

How to do Oracle patching? ›

The typical workflow for patching an Oracle Database home is as follows:
  1. Create a working copy of the Oracle Database that you want to patch, in this case DB122 .
  2. Apply the patch to the working copy you created.
  3. Test and validate the patched working copy.

What is the difference between a security update and a security patch? ›

Updates add new features or improve how existing features work. Patches, on the other hand, address security vulnerabilities. Updates and patches are often bundled together when a new version of the updated and patched software application is released.

How long do security updates last? ›

At the time of writing, Google promises Android updates for its Pixel phones for at least three years. For flagship Samsung Galaxy phones, the software update guarantee is for four years, and for the latest Fairphone 5, it's five years.

How often does Oracle release patches? ›

Oracle Critical Patch Updates are released quarterly. Since April 2022, Critical Patch Updates are released at around 1 p.m. Pacific Time on the third Tuesday of January, April, July, and October (They were previously released on the Tuesday closest to the 17th of the month in January, April, July, and October).

What is patch advisory? ›

Application Vulnerability Assessments. PatchAdvisor provides professional application level security assessments identifying vulnerabilities on COTS, GOTS and custom software packages.

Why is an update patch process crucial? ›

Patch management is the process of applying updates to software, drivers, and firmware to protect against vulnerabilities. Effective patch management also helps ensure the best operating performance of systems, boosting productivity.

What is patch conflict in Oracle? ›

All patches may not be compatible with one another. For example, if a patch has been applied, all the bugs fixed by that patch could reappear after another patch is applied. This is called a conflict situation. OPatch detects such situations and raises an error when a it detects a conflict.

Top Articles
50 Mediterranean Diet Recipe Favorites
Chewy & Soft Oatmeal Cookies Recipe | Crazy for Crust
Thedirtyship
Ann Taylor Assembly Row
Wowhead Filling The Cages
Poochies Liquor Store
Everything We Know About Wenwen Han and Her Rise To Stardom
Accident On May River Road Today
Cratebrowser
Ge Tracker Awakener Orb
Six Broadway Wiki
Martimelons
Calculator Souo
Do you want to do a backbend?
Huniepop Jessie Questions And Answers
NEU: LEAKSHIELD - das sicherste Flüssigkeits-Kühlsystem der Welt - Wasserkühlung
Minnesota Gophers Highlights
Breakroom Bw
Craigslist Ct Pets
San Antonio Craigslist Free
American Flat Track Season Resumes At Orange County Fair Speedway - FloRacing
Swissport Timecard
Hannah Palmer Listal
Dumb Money, la recensione: Paul Dano e quel film biografico sul caso GameStop
Live Stream Portal
David Goggins Is A Fraud
Pcc Skilled Nursing Login
Stuckey Furniture
Itsfunnydude11 Wisconsin Volleyball Team : Itsfunnydude11 Twitter, Itsfunnydude11 Reddit – Know About It ! - Opensquares
Conan Exiles Meteor Shower Command
Dutchessravenna N Word
Rare Rides: The 1970 Chevrolet Chevelle SS454 LS6 Convertible - Street Muscle Rare Rides
Unblocked Games 66E
Help with Finding Parts for Your Vehicle
Did Taylor Swift Date Greg Gutfeld
Glassbox Eyecare
Craigslist Lake Charles
Tények este teljes adás, 2024. április 26., péntek
Barbarian Frenzy Build with the Horde of the Ninety Savages set (Patch 2.7.7 / Season 32)
Matt Laubhan Salary
10439 Gliding Eagle Way Land O Lakes Fl 34638
P1 Offshore Schedule
Cetaphil Samples For Providers
Uncg Directions
Pirates Bay Knaben
Craigslist Ri Rhode Island
Before Trump, neo-Nazis pushed false claims about Haitians as part of hate campaign
Craigslist Farm And Garden Atlanta Georgia
What Does Wmt Contactless Mean
Craigslist Cars By Owner
Liberty 1098-T
Larry's Country Diner LIVE! - 2024 Tickets - Branson Travel Office
Latest Posts
Article information

Author: Duncan Muller

Last Updated:

Views: 6131

Rating: 4.9 / 5 (59 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Duncan Muller

Birthday: 1997-01-13

Address: Apt. 505 914 Phillip Crossroad, O'Konborough, NV 62411

Phone: +8555305800947

Job: Construction Agent

Hobby: Shopping, Table tennis, Snowboarding, Rafting, Motor sports, Homebrewing, Taxidermy

Introduction: My name is Duncan Muller, I am a enchanting, good, gentle, modern, tasty, nice, elegant person who loves writing and wants to share my knowledge and understanding with you.