Quantcast
Channel: Tenable Blog
Viewing all articles
Browse latest Browse all 1935

Oracle July 2022 Critical Patch Update Addresses 188 CVEs

$
0
0
Oracle July 2022 Critical Patch Update Addresses 188 CVEs

Oracle addresses 188 CVEs in its third quarterly update of 2022 with 349 patches, including 66 critical updates.

Background

On July 19, Oracle released its Critical Patch Update (CPU) for July 2022, the third quarterly update of the year. This CPU contains fixes for 188 CVEs in 349 security updates across 32 Oracle product families. Out of the 349 security updates published this quarter, 66 patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 146, followed by medium severity patches at 133.

This quarter’s update includes over 90 medium severity CVEs, followed by 65 high severity CVEs.

SeverityIssues PatchedCVEs
Critical6629
High14665
Medium13390
Low44
Total349188

Analysis

This quarter, the Oracle Financial Services Applications product family contained the highest number of patches at 59, accounting for 16.91% of the total patches, followed by Oracle Communications with 56 patches, which accounted for 16.05% of the total patches.

Oracle did not include security patches for five product families:

  • Oracle Autonomous Health Framework
  • Oracle Berkeley DB
  • Oracle Blockchain Platform
  • Oracle NoSQL Database
  • Oracle SQL Developer

While these five product families did not receive security patches, Oracle notes that there are third-party patches included as part of its CPU release that affect them:

Oracle Product FamilyComponentCVE
Oracle Autonomous Health FrameworkAutonomous Health Framework (NumPy)CVE-2021-41495
Oracle Autonomous Health FrameworkAutonomous Health Framework (NumPy)CVE-2021-41496
Oracle Autonomous Health FrameworkAutonomous Health Framework (Python)CVE-2021-29396
Oracle Autonomous Health FrameworkAutonomous Health Framework (Python)CVE-2021-29921
Oracle Autonomous Health FrameworkTrace File Analyzer (jackson-databind)CVE-2020-36518
Oracle Berkeley DBData Store (Apache Log4j)CVE-2021-4104
Oracle Berkeley DBData Store (Apache Log4j)CVE-2022-23302
Oracle Berkeley DBData Store (Apache Log4j)CVE-2022-23305
Oracle Berkeley DBData Store (Apache Log4j)CVE-2022-23307
Oracle Blockchain PlatformBlockchain Cloud Service Console (OpenSSH)CVE-2021-41617
Oracle NoSQL DatabaseAdministration (Netty)CVE-2021-43797
Oracle SQL DeveloperOracle SQL Developer (Apache PDFBox)CVE-2021-31811
Oracle SQL DeveloperOracle SQL Developer (Apache PDFBox)CVE-2021-31812

A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.

Oracle Product FamilyNumber of PatchesRemote Exploit without Authentication
Oracle Financial Services Applications5938
Oracle Communications5645
Oracle Fusion Middleware3832
Oracle MySQL3410
Oracle Supply Chain2419
Oracle Communications Applications1712
Oracle Retail Applications1713
Oracle Commerce1210
Oracle PeopleSOft119
Oracle Database Server91
Oracle Construction and Engineering74
Oracle Systems72
Oracle E-Business Suite65
Oracle Enterprise Manager66
Oracle Health Sciences Applications63
Oracle JD Edwards63
Oracle Java SE54
Oracle GoldenGate42
Oracle Big Data Graph33
Oracle Food and Beverage Applications33
Oracle HealthCare Applications32
Oracle Policy Automation31
Oracle REST Data Services22
Oracle Hospitality Applications22
Oracle Virtualization20
Oracle Essbase10
Oracle Global Lifecycle Management10
Oracle Graph Server and Client10
Oracle Spatial Studio10
Oracle TimesTen In-Memory Database11
Oracle Siebel CRM10
Oracle Utilities Applications11

Oracle out-of-band security alert for E-Business Suite

In some instances, Oracle will publish a security alert outside of its normal CPU process. Following Oracle’s April 2022 CPU, it published an alert on May 19 for CVE-2022-21500, a vulnerability in Oracle E-Business Suite version 12.2 that could allow an attacker to self-register a new user account on a publicly accessible E-Business Suite system. Successful exploitation could grant an attacker access to the system and allow them to collect personal information on the registered employees on the system including first and last names, email addresses and potentially more sensitive details.

For organizations that did not apply the patch for CVE-2022-21500 in May, applying this quarter’s CPU includes this fix.

Oracle patches Spring4Shell across a number of product families

As part of its July 2022 CPU, Oracle released additional patches for CVE-2022-22965, a remote code execution vulnerability in the Spring Core Framework, referred to as Spring4Shell by the security research community, that was originally disclosed in March. The patches in the July 2022 CPU that address Spring4Shell across a variety of Oracle products are summarized in the table below:

Oracle ProductComponent
Oracle Commerce PlatformEndeca Integration (Spring Framework)
Oracle Communications Unified Inventory ManagementTMF APIs (Spring Framework)
Oracle Communications Billing and Revenue Management - Elastic Charging EngineCharging Server (Spring Framework)
Oracle Communications Cloud Native Core Binding Support FunctionBSF (Spring Framework)
Oracle Communications Cloud Native Core Security Edge Protection ProxySEPP (Spring Framework)
Oracle Communications Cloud Native Core Service Communication ProxySCP (Spring Boot)
Oracle Primavera GatewayAdmin (Spring Framework)
Oracle Enterprise Manager for MySQL DatabaseEM Plugin: General (Spring Framework)
Oracle WebLogic ServerThird Party Tools, Samples (Spring Framework)
Oracle BI PublisherWeb Service API (Spring Framework)
Oracle Business Intelligence Enterprise EditionAnalytics Server (Spring Framework)
Oracle Data IntegratorRuntime Java agent for ODI (Spring Framework)
Oracle Identity Management SuiteInstaller (Spring Framework)
Oracle Identity Manager ConnectorGeneral and Misc (Spring Framework)
Oracle Middleware Common Libraries and ToolsThird Party Patch (Spring Framework)
Oracle Retail Bulk Data IntegrationBDI Job Scheduler (Spring Framework)
Oracle Retail Customer Management and Segmentation FoundationSecurity (Spring Framework)
Oracle Retail Financial IntegrationPeopleSoft Integration Bugs (Spring Framework)
Oracle Retail Integration BusRIB Kernal (Spring Framework)
Oracle Retail Merchandising SystemFoundation (Spring Framework)

Identifying affected systems

A list of Tenable plugins to identify these vulnerabilities will appear here as they’re released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.

Get more information

Join Tenable's Security Response Team on the Tenable Community.

Learn more about Tenable, the first Cyber Exposure platform for holistic management of your modern attack surface.

Get a free 30-day trial of Tenable.io Vulnerability Management.


Viewing all articles
Browse latest Browse all 1935

Trending Articles