On April 15, 2025, Oracle published its latest Critical Patch Update (CPU), delivering a sweeping set of 378 new security patches across its expansive product portfolio.
This quarterly update is vital for organizations relying on Oracle software, as it addresses vulnerabilities in Oracle’s code as well as in third-party components embedded within Oracle products.
The update highlights the persistent risk posed by unpatched systems, with Oracle reiterating its recommendation for customers to apply these updates without delay.
The April 2025 CPU covers a broad array of Oracle product families, including:
Each product family’s risk matrix details newly addressed vulnerabilities, their Common Vulnerabilities and Exposures (CVE) identifiers, and their risk scores based on the Common Vulnerability Scoring System (CVSS) v3.1.
Remotely Exploitable Vulnerabilities: A significant number of the patched vulnerabilities can be exploited remotely without authentication.
For example, in Oracle Communications, 82 of the 103 vulnerabilities addressed may be exploited over a network without user credentials.
Similarly, Oracle Database, Fusion Middleware, and MySQL products also include multiple remotely exploitable flaws1.
High-Risk Components and Protocols: Critical vulnerabilities were found in widely used components such as Apache Tomcat, Apache Mina, OpenSSL, Netty, Spring Framework, and json-smart.
Many issues affect both HTTP and secure protocols like HTTPS and TLS, underscoring the importance of patching both secure and insecure variants1.
Third-Party Component Risks: Numerous vulnerabilities stem from third-party libraries (e.g., Apache Commons IO, libxml2, Google Protobuf-Java, Eclipse Jetty), some of which are not directly exploitable in the Oracle context but are patched as a precaution.
Oracle now provides VEX (Vulnerability Exploitability eXchange) justifications for such cases1.
Product Versions and Support: Patches are available only for versions under Premier or Extended Support. Oracle strongly advises upgrading unsupported versions, as older releases are likely vulnerable but do not receive new patches1.
While immediate patching is the only long-term solution, Oracle suggests temporary workarounds such as blocking network protocols required by an attack or removing unnecessary privileges.
However, these may disrupt application functionality and are not substitutes for applying official patches1.
| CVE ID | Product/Component | Protocol | Remote Exploit | CVSS Base Score | Confidentiality | Integrity | Availability |
|---|---|---|---|---|---|---|---|
| CVE-2024-52046 | Apache Mina (Multiple) | HTTP | Yes | 9.8 | High | High | High |
| CVE-2024-56337 | Apache Tomcat (Multiple) | HTTP | Yes | 9.8 | High | High | High |
| CVE-2024-40896 | libxml2 | HTTP | Yes | 9.1 | None | High | High |
| CVE-2025-30727 | Oracle Scripting | HTTP | Yes | 9.8 | High | High | High |
| CVE-2024-11053 | curl | HTTP/TLS | Yes | 9.1 | High | High | None |
| CVE-2024-23807 | Apache Xerces-C++ (JD Edwards) | HTTP | Yes | 9.8 | High | High | High |
This table represents a subset of the highest-risk vulnerabilities from the April 2025 CPU. For a full risk matrix, refer to Oracle’s advisory documentation.
Oracle CPUs are released quarterly, with the next date set for July 15, 2025, and subsequent quarters.
Organizations are urged to maintain up-to-date patching practices and leverage Oracle’s risk matrices to prioritize remediation efforts.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates
The post Oracle Releases Security Update Patching 378 Vulnerabilities appeared first on Cyber Security News.
Lenovo's most powerful Legion gaming PC is back in stock, but not only that, it's…
Warning: This review contains full spoilers for Star Wars: Maul - Shadow Lord Episodes 9…
30 years. It feels like a lifetime (and for some of us it us, including…
Resident Evil Requiem producer Masato Kumazawa has said Capcom sees the drama surrounding the DLSS…
The Pitt star Isa Briones has called out "f**king disrespectful" fans for yelling references while…
Pinecone has released Pinecone Nexus, a knowledge engine designed to move reasoning from retrieval to…
This website uses cookies.