Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No cookies to display.

URL has been copied successfully!
Oracle April 2025 Critical Patch Update Addresses 171 CVEs
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Oracle April 2025 Critical Patch Update Addresses 171 CVEs

Oracle addresses 171 CVEs in its second quarterly update of 2025 with 378 patches, including 40 critical updates.

Background

On April 15, Oracle released its Critical Patch Update (CPU) for April 2025, the second quarterly update of the year. This CPU contains fixes for 171 unique CVEs in 378 security updates across 32 Oracle product families. Out of the 378 security updates published this quarter, 10.6% of patches were assigned a critical severity. Medium severity patches accounted for the bulk of security patches at 54.5%, followed by high severity patches at 32.3%. This quarter’s update includes 40 critical patches across 15 CVEs.

Severity Issues Patched CVEs
Critical 40 15
High 122 52
Medium 206 98
Low 10 6
Total 378 171

Analysis

This quarter, the Oracle SQL Developer product family contained the highest number of patches at 103, accounting for 27.3% of the total patches, followed by Oracle Hyperion at 43 patches, which accounted for 11.4% of the total patches. A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.

Oracle Product Family Number of Patches Remote Exploit without Auth
Oracle SQL Developer 103 82
Oracle Hyperion 43 2
Oracle Secure Backup 42 35
Oracle Communications 34 22
Oracle E-Business Suite 31 26
Oracle Commerce 16 11
Oracle Enterprise Manager 15 11
Oracle JD Edwards 11 11
Oracle Hospitality Applications 8 5
Oracle Database Server 7 3
Oracle TimesTen In-Memory Database 7 6
Oracle REST Data Services 6 5
Oracle Analytics 6 5
Oracle Essbase 4 2
Oracle Communications Applications 4 4
Oracle Insurance Applications 4 1
Oracle MySQL 4 2
Oracle Policy Automation 4 4
Oracle Construction and Engineering 3 2
Oracle Financial Services Applications 3 2
Oracle Food and Beverage Applications 3 2
Oracle Java SE 3 3
Oracle PeopleSoft 3 2
Oracle Supply Chain 3 0
Oracle NoSQL Database 2 2
Oracle Retail Applications 2 0
Oracle Siebel CRM 2 2
Oracle Application Express 1 1
Oracle Autonomous Health Framework 1 0
Oracle GoldenGate 1 1
Oracle Graph Server and Client 1 0
Oracle Fusion Middleware 1 1

Solution

Customers are advised to apply all relevant patches in this quarter’s CPU. Please refer to the April 2025 advisory for full details.

Identifying affected systems

A list of Tenable plugins to identify these vulnerabilities will appear here as they’re released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.

Get more information

Oracle Critical Patch Update Advisory – April 2025 Oracle April 2025 Critical Patch Update Risk Matrices Oracle Advisory to CVE Map Join Tenable’s Security Response Team on the Tenable Community.
Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.

First seen on securityboulevard.com

Jump to article: securityboulevard.com/2025/04/oracle-april-2025-critical-patch-update-addresses-171-cves/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link