Quantcast
Channel: Tenable Blog
Viewing all articles
Browse latest Browse all 1935

Oracle April 2022 Critical Patch Update Addresses 221 CVEs

$
0
0

Oracle addresses 221 CVEs in its second quarterly update of 2022 with 520 patches, including 27 critical updates.

Background

On April 19, Oracle released its Critical Patch Update (CPU) for April 2022, the second quarterly update of the year. This CPU contains fixes for 221 CVEs in 520 security updates across 31 Oracle product families. Out of the 520 security updates published this quarter, 14.8% of patches were assigned critical severity. Medium severity patches accounted for the bulk of the release at 55.2%, followed by high severity patches at 27.1%.

This quarter’s update includes 77 critical patches across 27 CVEs.

SeverityIssues PatchedCVEs
Critical7727
High14169
Medium287114
Low1511
Total520221

Analysis

This quarter, the Oracle Communications product family contained the highest number of patches at 149, accounting for 28.6% of the total patches, followed by Oracle Fusion Middleware at 54 patches, which accounted for 10.4% of the total patches.

Two CVEs receive the highest possible CVSS Score

This month's CPU release included two CVEs that were given a CVSSv3 score of 10.0, the highest possible severity.

CVE-2022-22947 is a vulnerability impacting the Oracle Communications product family that can be exploited by an unauthenticated attacker with network access via HTTP. This vulnerability would allow a remote attacker to exploit arbitrary code when the Spring Cloud gateway actuator is enabled and unsecured.

CVE-2022-21431 is a vulnerability in the Connection Manager component of the Oracle Communications Billing and Revenue Management product that can be exploited by an unauthenticated attacker with network access via TCP to gain full control of the Billing and Revenue Management service; however, Oracle indicates that exploitation of this vulnerability could “significantly impact additional products.”

Oracle addresses “psychic signatures” vulnerability in Java

Additionally, Oracle addressed CVE-2022-21449, a cryptographic signature vulnerability in Java 15, 16, 17 and 18. It has been referred to as a “psychic signatures” vulnerability by Neil Madden, security architect at Forgerock, who published a detailed blog post about the flaw. While Oracle assigned a CVSSv3 score of 7.5 to the vulnerability, Madden says that Forgerock assigned a CVSSv3 score of 10.0.

Three product families receive only third party patches

While 31 product families received security patches this quarter, Oracle did not include security patches for three product families:

  • Oracle Global Lifecycle Management
  • Oracle NoSQL Database
  • Oracle Secure Backup

While these three product families did not receive security patches, Oracle notes that there are third-party patches included as part of its CPU release:

Oracle Product FamilyComponentCVE
Oracle NoSQL DatabaseAdministration (Netty)CVE-2021-37137
Oracle NoSQL DatabaseAdministration (Netty)CVE-2021-21290
Oracle NoSQL DatabaseAdministration (Netty)CVE-2021-21295
Oracle NoSQL DatabaseAdministration (Netty)CVE-2021-21409
Oracle NoSQL DatabaseAdministration (Netty)CVE-2021-30129
Oracle NoSQL DatabaseAdministration (Netty)CVE-2021-37136
Oracle NoSQL DatabaseAdministration (Apache MINA SSHD)CVE-2021-30129
Oracle Secure BackupSecure Backup (Apache HTTP Server)CVE-2021-44790
Oracle Secure BackupSecure Backup (Apache HTTP Server)CVE-2021-32785
Oracle Secure BackupSecure Backup (Apache HTTP Server)CVE-2021-32786
Oracle Secure BackupSecure Backup (Apache HTTP Server)CVE-2021-32791
Oracle Secure BackupSecure Backup (Apache HTTP Server)CVE-2021-32792
Oracle Secure BackupSecure Backup (Apache HTTP Server)CVE-2021-44224
Oracle Secure BackupSecure Backup (PHP)CVE-2021-21703
Oracle Global Lifecycle Management OPatchCentralized Third Party Jars (Apache Commons Compress)CVE-2021-36090
Oracle Global Lifecycle Management OPatchCentralized Third Party Jars (Apache Commons Compress)CVE-2021-35515
Oracle Global Lifecycle Management OPatchCentralized Third Party Jars (Apache Commons Compress)CVE-2021-35516
Oracle Global Lifecycle Management OPatchCentralized Third Party Jars (Apache Commons Compress)CVE-2021-35517

Third party patches also include fixes for Apache Log4j

Oracle has also addressed multiple additional third party patches in this release, including fixes for vulnerabilities in Apache Log4j, most notably a remote code execution vulnerability dubbed Log4Shell and originally disclosed in December.

Third Party ComponentCVE
Apache TomcatCVE-2021-42340
Apache Log4jCVE-2021-44832
Apache Log4jCVE-2022-23305
Apache Xerces-JCVE-2022-23437
Apache KafkaCVE-2021-38153
JakartaCVE-2021-28170
GuavaCVE-2020-8908

A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.

Oracle Product FamilyNumber of PatchesRemote Exploit without Auth
Oracle Communications14998
Oracle Fusion Middleware5441
Oracle MySQL4311
Oracle Financial Services Applications4119
Oracle Communications Applications3922
Oracle Retail Applications3015
Oracle Systems2014
Oracle Blockchain Platform1514
Oracle PeopleSoft148
Oracle Hyperion124
Oracle Supply Chain115
Oracle Enterprise Manager107
Oracle HealthCare Applications105
Oracle JD Edwards88
Oracle Commerce73
Oracle Insurance Applications75
Oracle Java SE77
Oracle Hospitality Applications62
Oracle Virtualization61
Oracle Database Server50
Oracle GoldenGate54
Oracle E-Business Suite52
Oracle Construction and Engineering31
Oracle Health Sciences Applications31
Oracle Support Tools31
Oracle SQL Developer21
Oracle Autonomous Health Framework10
Oracle REST Data Services10
Oracle iLearning11
Oracle Taleo10
Oracle Utilities Applications10

Solution

Customers are advised to apply all relevant patches in this quarter’s CPU. Please refer to the April 2022 advisory for full details.

Identifying affected systems

A list of Tenable plugins to identify these vulnerabilities will appear here as they’re released.

Get more information

Join Tenable's Security Response Team on the Tenable Community.

Learn more about Tenable, the first Cyber Exposure platform for holistic management of your modern attack surface.

Get a free 30-day trial of Tenable.io Vulnerability Management.


Viewing all articles
Browse latest Browse all 1935

Trending Articles