Oracle’s second Critical Patch Update of 2020 addresses 450 CVEs across a record-breaking 397 security patches, including critical vulnerabilities in Oracle Fusion Middleware products.
Background
On April 14, Oracle released its Critical Patch Update (CPU) Advisory for April 2020 as part of its quarterly release of security patches. This update contains fixes for 450 CVEs in 397 security patches across multiple Oracle products. This quarter’s update smashes the previous records of 334 patches, with January 2020 and July 2018 in a tie for the previous record.
Analysis
This quarter’s CPU includes more than 30 critically rated CVEs across a wide range of Oracle products. The following is the full list of product families with vulnerabilities addressed in this month’s release along with the number of patches released.
Oracle Product Family | Number of Patches |
---|---|
Oracle E-Business Suite | 74 |
Oracle Fusion Middleware | 51 |
Oracle MySQL | 45 |
Oracle Communications Applications | 39 |
Oracle Financial Services Applications | 35 |
Oracle Retail Applications | 27 |
Oracle Virtualization | 19 |
Oracle Knowledge | 16 |
Oracle Java SE | 15 |
Oracle PeopleSoft | 14 |
Oracle Construction and Engineering | 12 |
Oracle Systems | 9 |
Oracle Database Server | 8 |
Oracle Enterprise Manager | 7 |
Oracle GraalVM | 5 |
Oracle JD Edwards | 4 |
Oracle Supply Chain | 4 |
Oracle Hyperion | 3 |
Oracle Health Sciences Applications | 2 |
Oracle Support Tools | 2 |
Oracle Utilities Applications | 2 |
Oracle Food and Beverage Applications | 1 |
Oracle Siebel CRM | 1 |
Oracle Global Lifecycle Management | 1 |
Oracle Secure Backup | 1 |
Solution
Customers are advised to apply all relevant patches provided by Oracle in this CPU. Please refer to the April 2020 advisory for full details.
Identifying affected systems
A list of Tenable plugins to identify these vulnerabilities will appear here as they’re released.
Get more information
- Oracle Critical Patch Update Advisory - April 2020
- Oracle Advisory to CVE Map
- Oracle April 2020 CPU Risk Matrices
Join Tenable's Security Response Team on the Tenable Community.
Learn more about Tenable, the first Cyber Exposure platform for holistic management of your modern attack surface.
Get a free 30-day trial of Tenable.io Vulnerability Management.