Quantcast
Channel: Tenable Blog
Viewing all articles
Browse latest Browse all 1935

Oracle October 2022 Critical Patch Update Addresses 179 CVEs

$
0
0
Oracle October 2022 Critical Patch Update Addresses 179 CVEs

Oracle addresses 179 CVEs in its fourth and final quarterly update of 2022 with 370 patches, including 56 critical updates.

Background

On October 18, Oracle released its Critical Patch Update (CPU) for October 2022, the fourth and final quarterly update of the year. This CPU contains fixes for 179 CVEs in 370 security updates across 27 Oracle product families. Out of the 370 security updates published this quarter, 56 patches were assigned a critical severity. Medium severity patches accounted for the bulk of security patches at 163, followed by high severity patches at 144.

This quarter’s update includes 83 medium severity CVEs, followed by 57 high severity CVEs and 7 low severity CVEs.

SeverityIssues PatchedCVEs
Critical5632
High14457
Medium16383
Low77
Total370179

Analysis

This quarter, the Oracle Communications product family contained the highest number of patches at 74, accounting for 20% of the total patches, followed by Oracle Fusion Middleware with 56 patches, which accounted for 15.14% of the total patches.

Oracle did not include security patches for five product families:

  • Oracle Airlines Data Model
  • Oracle Big Data Graph
  • Oracle NoSQL Database
  • Oracle SQL Developer
  • Oracle TimesTen In-Memory Database

While these five product families did not receive security patches, Oracle notes that there are third-party patches included as part of its CPU release that affect them:

Oracle Product FamilyComponentCVE
Oracle Airlines Data ModelInstallation (Apache Commons BeanUtils)CVE-2019-10086
Oracle Airlines Data ModelInstallation (Apache Commons IO)CVE-2021-29425
Oracle Airlines Data ModelInstallation (Apache Groovy)CVE-2020-17521
Oracle Airlines Data ModelInstallation (Apache Log4j)CVE-2021-4104
Oracle Airlines Data ModelInstallation (Nimbus JOSE+JWT)CVE-2019-17195
Oracle Airlines Data ModelInstallation (Spring Framework)CVE-2021-22118
Oracle Airlines Data ModelInstallation (Spring Framework)CVE-2020-5421
Oracle Airlines Data ModelInstallation (jackson-databind)CVE-2020-9546
Oracle Airlines Data ModelInstallation (jackson-databind)CVE-2020-10650
Oracle Airlines Data ModelInstallation (jackson-databind)CVE-2020-10672
Oracle Airlines Data ModelInstallation (jackson-databind)CVE-2020-10673
Oracle Airlines Data ModelInstallation (jackson-databind)CVE-2020-10968
Oracle Airlines Data ModelInstallation (jackson-databind)CVE-2020-10969
Oracle Airlines Data ModelInstallation (jackson-databind)CVE-2020-11111
Oracle Airlines Data ModelInstallation (jackson-databind)CVE-2020-11112
Oracle Airlines Data ModelInstallation (jackson-databind)CVE-2020-11113
Oracle Airlines Data ModelInstallation (jackson-databind)CVE-2020-14195
Oracle Airlines Data ModelInstallation (jackson-databind)CVE-2020-25649
Oracle Airlines Data ModelInstallation (jackson-databind)CVE-2020-36189
Oracle Airlines Data ModelInstallation (jackson-databind)CVE-2020-9547
Oracle Airlines Data ModelInstallation (jackson-databind)CVE-2020-9548
Oracle Big Data Spatial and GraphBig Data Graph (Apache Tomcat)CVE-2022-34305
Oracle NoSQL DatabaseAdministration (Google Gson)CVE-2022-25647
Oracle NoSQL DatabaseAdministration (jackson-databind)CVE-2020-36518
Oracle SQL DeveloperInstall (Apache Batik)CVE-2020-11987
Oracle SQL DeveloperInstall (Apache Kafka)CVE-2021-38153
Oracle SQL DeveloperInstall (Apache Kafka)CVE-2021-26291
Oracle TimesTen In-Memory DatabaseKubernetes Operator (Golang Go)CVE-2022-28327
Oracle TimesTen In-Memory DatabaseKubernetes Operator (Golang Go)CVE-2022-24675

A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.

Oracle Product FamilyNumber of PatchesRemote Exploit without Authentication
Oracle Communications7464
Oracle Fusion Middleware5643
Oracle MySQL3711
Oracle Communications Applications2721
Oracle Retail Applications2721
Oracle Financial Services Applications2416
Oracle Siebel CRM1412
Oracle Supply Chain139
Oracle JD Edwards109
Oracle Virtualization103
Oracle Java SE99
Oracle Database Server81
Oracle PeopleSoft84
Oracle Systems84
Oracle Utilities Applications64
Oracle Construction and Engineering52
Oracle E-Business Suite54
Oracle Enterprise Manager54
Oracle HealthCare Applications54
Oracle Insurance Applications53
Oracle Hospitality Applications42
Oracle Commerce32
Oracle Essbase21
Oracle GoldenGate21
Oracle Communications Data Model10
Oracle Secure Backup11
Oracle Hyperion11
Oracle Airlines Data Model00
Oracle Big Data Graph00
Oracle NoSQL Database00
Oracle SQL Developer00
Oracle TimesTen In-Memory Database00

2021 Critical Patch Update totals: 854 CVEs patched

The combined total of CVEs patched in this year’s CPUs was 854. This year saw a 7.27% decrease in the number of CVEs patched compared to 2021, when Oracle patched a total of 921 CVEs.

The first two quarters in both 2021 and 2022 saw the most patches released, 487 in 2022 and 459 in 2021. In 2021, Q3 and Q4 had an equal number of patches (231), whereas Q3 and Q4 of 2022 saw a marked decrease in patches (188 and 179 respectively).

Schedule for quarterly patch updates for 2023

Looking ahead to 2023, Oracle has specified the dates for upcoming Oracle CPUs:

  1. January 17, 2023
  2. April 18, 2023
  3. July 18, 2023
  4. October 17, 2023

Identifying affected systems

A list of Tenable plugins to identify these vulnerabilities will appear here as they’re released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.

Get more information

Join Tenable's Security Response Team on the Tenable Community.

Learn more about Tenable, the first Cyber Exposure platform for holistic management of your modern attack surface.

Get a free 30-day trial of Tenable.io Vulnerability Management.


Viewing all articles
Browse latest Browse all 1935

Trending Articles