Oracle Critical Patch Update, July 2025 Security Update Review


Oracle released its second quarterly edition of this year’s Critical Patch Update. The update received patches for 309 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.

In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 84, constituting about 27% of the total patches released. Oracle MySQL and Oracle Fusion Middleware followed, with 40 and 36 security patches.

228 of the 309 security patches provided by the April Critical Patch Update (about 74%) are for non-Oracle CVEs, such as open-source components included and exploitable in the context of their Oracle product distributions.

This batch of security patches received 15 updates for Oracle Database products. The following is the product-wise distribution:

  • Six new security updates for Oracle Database Server with a maximum reported CVSS Base Score of 8.8.
    • One of these updates applies to client-only deployments of the Oracle Database.
  • One new security update for Oracle Application Express with a maximum reported CVSS Base Score of 9.0.
  • One new security update for Oracle Blockchain Platform with a maximum reported CVSS Base Score of 6.5.
  • Five new security updates for Oracle GoldenGate with a maximum reported CVSS Base Score of 7.5.
  • One new security update for Oracle NoSQL Database with a maximum reported CVSS Base Score of 3.7.
  • One new security update for Oracle REST Data Services with a maximum reported CVSS Base Score of 6.1.

In these security updates, Oracle has covered product families, including Oracle Database Server, Oracle Application Express, Oracle Blockchain Platform, Oracle GoldenGate, Oracle NoSQL Database, Oracle REST Data Services, Oracle Commerce, Oracle Communications Applications, Oracle Communications, Oracle Construction and Engineering, Oracle E-Business Suite, Oracle Enterprise Manager, Oracle Financial Services Applications, Oracle Fusion Middleware, Oracle Analytics, Oracle HealthCare Applications, Oracle Hospitality Applications, Oracle Hyperion, Oracle Insurance Applications, Oracle Java SE, Oracle JD Edwards, Oracle MySQL, Oracle PeopleSoft, Oracle Retail Applications, Oracle Siebel CRM, Oracle Supply Chain, Oracle Utilities Applications, Oracle Virtualization.

Qualys QID Coverage

 Qualys has released the following QIDS mentioned in the table:

QIDs Title
20487 Oracle Database 21c Critical Patch Update – July 2025
20488 Oracle Database 19c Critical Patch Update – July 2025
20490 Oracle MySQL Server July 2025 Critical Patch Update (CPUJUL2025)
383578 Oracle Java Standard Edition (SE) Critical Patch Update – July 2025 (CPUJUL2025)
383580 Oracle Coherence July 2025 Security Patch Update (CPUJUL2025)
383586 Oracle Managed Virtualization (VM) VirtualBox Multiple Security Vulnerabilities (CPUJUL2025)
296127 Oracle Solaris 11.4 Support Repository Update (SRU) 83.195.1 Missing (CPUJUL2025)
87583 Oracle WebLogic Server Multiple Vulnerabilities (CPUJUL2025)

Note: The table will be updated with additional QIDs once released.

Notable Oracle Vulnerabilities Patched

Oracle Communications

This Critical Patch Update for Oracle Communications received 84 security patches. Out of these, 50 vulnerabilities can be exploited over a network without user credentials.

CVE-2024-25638, CVE-2025-48734, CVE-2024-47606, CVE-2024-1135, CVE-2025-23016, CVE-2025-27363, and CVE-2023-27349 in different Oracle Communications products have high severity ratings.

Oracle MySQL

This Critical Patch Update for Oracle MySQL received 40 security patches. Out of these, three vulnerabilities can be exploited over a network without user credentials.

CVE-2024-9287 and CVE-2025-32415 in MySQL Workbench have high severity ratings. An attacker may exploit these vulnerabilities without privileges in a low-complexity network attack.

Oracle Fusion Middleware

This Critical Patch Update for Oracle Fusion Middleware received 36 security patches. Out of these, 22 vulnerabilities can be exploited over a network without user credentials.

CVE-2025-31651 and CVE-2024-52046 in different Oracle Fusion Middleware products have critical severity ratings with a CVSS score of 9.8. A remote attacker may exploit these vulnerabilities without privileges in a low-complexity network attack.

Oracle Communications Applications

This Critical Patch Update for Oracle Communications Applications received 29 security patches. One of the vulnerabilities can be exploited over a network without user credentials.

CVE-2025-48734 and CVE-2024-56406 in different Oracle Communications Applications products have high severity ratings with a CVSS score of 8.8 and 8.6. A remote attacker may exploit these vulnerabilities without privileges in a low-complexity network attack.

Oracle Financial Services Applications

This Critical Patch Update for Oracle Financial Services Applications received 18 security patches. Out of these, 13 vulnerabilities can be exploited over a network without user credentials.

CVE-2025-48734 impacting different Oracle Financial Services Applications products has high severity ratings with a CVSS score of 8.8. A remote attacker may exploit these vulnerabilities without privileges in a low-complexity network attack.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *