Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Oracle April 2025 Critical Patch Update Addresses 171 CVEs



Tenable Blog Header Image Oracle Critical Patch Update

Oracle addresses 171 CVEs in its second quarterly update of 2025 with 378 patches, including 40 critical updates.

Background

On April 15, Oracle released its Critical Patch Update (CPU) for April 2025, the second quarterly update of the year. This CPU contains fixes for 171 unique CVEs in 378 security updates across 32 Oracle product families. Out of the 378 security updates published this quarter, 10.6% of patches were assigned a critical severity. Medium severity patches accounted for the bulk of security patches at 54.5%, followed by high severity patches at 32.3%.

This quarter’s update includes 40 critical patches across 15 CVEs.

SeverityIssues PatchedCVEs
Critical4015
High12252
Medium20698
Low106
Total378171

Analysis

This quarter, the Oracle SQL Developer product family contained the highest number of patches at 103, accounting for 27.3% of the total patches, followed by Oracle Hyperion at 43 patches, which accounted for 11.4% of the total patches.

A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.

Oracle Product FamilyNumber of PatchesRemote Exploit without Auth
Oracle SQL Developer10382
Oracle Hyperion432
Oracle Secure Backup4235
Oracle Communications3422
Oracle E-Business Suite3126
Oracle Commerce1611
Oracle Enterprise Manager1511
Oracle JD Edwards1111
Oracle Hospitality Applications85
Oracle Database Server73
Oracle TimesTen In-Memory Database76
Oracle REST Data Services65
Oracle Analytics65
Oracle Essbase42
Oracle Communications Applications44
Oracle Insurance Applications41
Oracle MySQL42
Oracle Policy Automation44
Oracle Construction and Engineering32
Oracle Financial Services Applications32
Oracle Food and Beverage Applications32
Oracle Java SE33
Oracle PeopleSoft32
Oracle Supply Chain30
Oracle NoSQL Database22
Oracle Retail Applications20
Oracle Siebel CRM22
Oracle Application Express11
Oracle Autonomous Health Framework10
Oracle GoldenGate11
Oracle Graph Server and Client10
Oracle Fusion Middleware11

Solution

Customers are advised to apply all relevant patches in this quarter’s CPU. Please refer to the April 2025 advisory for full details.

Identifying affected systems

A list of Tenable plugins to identify these vulnerabilities will appear here as they’re released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.

Get more information

Join Tenable's Security Response Team on the Tenable Community.
Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.


Cybersecurity news you can use

Enter your email and never miss timely alerts and security guidance from the experts at Tenable.