Quantcast
Channel: Tenable Blog
Viewing all articles
Browse latest Browse all 1935

Oracle January 2023 Critical Patch Update Addresses 183 CVEs

$
0
0
Oracle January 2023 Critical Patch Update Addresses 183 CVEs

Oracle addresses 183 CVEs in its first quarterly update of quarterly with 327 patches, including 71 critical updates.

Background

On January 17, Oracle released its

This quarter’s update includes 71 critical patches across 32 CVEs.

SeverityIssues PatchedCVEs
Critical7132
High14674
Medium10471
Low66
Total327183

Analysis

This quarter, the Oracle Spatial Studio product family contained the highest number of patches at 79, accounting for 24.1% of the total patches, followed by Oracle E-Business Suite at 50 patches, which accounted for 15.3% of the total patches.

Of the 327 patches, 49 patch CVEs released from 2018 - 2021, 10 of which were given a CVSSv3 score greater than 9. This means legacy vulnerabilities account for 14.9% of the total patches and 14.1% of critical patches. These 49 patches include 5 patches for CVE-2021-44832, a Log4j vulnerability released at the end of December 2021, and though it was given a lower CVSSv3 and is less likely to be exploited than Log4Shell, its inclusion highlights that there are still Log4j vulnerabilities in many applications used in production environments.

A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.

Oracle Product FamilyNumber of PatchesRemote Exploit without Authentication
Oracle Spatial Studio7963
Oracle E-Business Suite5039
Oracle Graph Server and Client3931
Oracle Hyperion378
Oracle Communications1612
Oracle Commerce1210
Oracle Insurance Applications1210
Oracle Database Server91
Oracle MySQL85
Oracle TimesTen In-Memory Database74
Oracle Construction and Engineering72
Oracle Siebel CRM77
Oracle PeopleSoft66
Oracle Supply Chain61
Oracle Financial Services Applications42
Oracle HealthCare Applications44
Oracle Essbase30
Oracle Communications Applications32
Oracle Big Data Graph21
Oracle GoldenGate22
Oracle Enterprise Manager22
Oracle Fusion Middleware22
Oracle Hospitality Applications21
Oracle JD Edwards21
Oracle Retail Applications21
Oracle Global Lifecycle Management10
Oracle Food and Beverage Applications10
Oracle Health Sciences Applications11
Oracle Java SE11

Solution

Customers are advised to apply all relevant patches in this quarter’s CPU. Please refer to the January 2023 advisory for full details.

Identifying affected systems

A list of Tenable plugins to identify these vulnerabilities will appear here as they’re released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.

Get more information

Join Tenable's Security Response Team on the Tenable Community.

Learn more about Tenable, the first Cyber Exposure platform for holistic management of your modern attack surface.

Get a free 30-day trial of Tenable.io Vulnerability Management.


Viewing all articles
Browse latest Browse all 1935

Trending Articles