Oracle July 2025 Critical Patch Update Addresses 165 CVEs
Oracle在2025年第三季度第三次更新中发布了309个安全补丁,修复了165个CVE漏洞,其中包括9个关键补丁。高、中、低危漏洞分别占比46.6%、43.7%和9.7%。Oracle REST Data Services产品修复最多。 2025-7-15 20:59:38 Author: www.tenable.com(查看原文) 阅读量:13 收藏

A title slide announcing the Oracle Critical Patch Update for July 2025 (Q3). The slide is branded with the Tenable Research Special Operations logo and features a central yellow database icon against a background with colorful striped borders.

Oracle addresses 165 CVEs in its third quarterly update of 2025 with 309 patches, including nine critical updates.

Background

On July 15, Oracle released its Critical Patch Update (CPU) for July 2025, the third quarterly update of the year. This CPU contains fixes for 165 unique CVEs in 309 security updates across 28 Oracle product families. Out of the 309 security updates published this quarter, 2.9% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 46.6%, followed by medium severity patches at 43.7%.

A donut chart illustrating the Oracle Critical Patch Update for July 2025. It shows that out of a total of 309 security patches, 144 are rated "High" severity, 135 are "Medium", 21 are "Low", and 9 are "Critical". The two highest severity categories, High and Medium, make up over 90% of the total patches.

This quarter’s update includes nine critical patches across five CVEs.

SeverityIssues PatchedCVEs
Critical95
High14459
Medium13591
Low2110
Total309165

Analysis

This quarter, the Oracle REST Data Services product family contained the highest number of patches at 84, accounting for 27.2% of the total patches, followed by Oracle Hospitality Applications at 40 patches, which accounted for 12.9% of the total patches.

A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.

Oracle Product FamilyNumber of PatchesRemote Exploit without Auth
Oracle REST Data Services8450
Oracle Hospitality Applications403
Oracle Communications3622
Oracle NoSQL Database291
Oracle Communications Applications1813
Oracle Analytics1110
Oracle Insurance Applications118
Oracle TimesTen In-Memory Database93
Oracle JD Edwards88
Oracle Hyperion73
Oracle PeopleSoft70
Oracle Database Server60
Oracle Java SE65
Oracle MySQL65
Oracle Blockchain Platform52
Oracle Construction and Engineering52
Oracle Financial Services Applications41
Oracle E-Business Suite32
Oracle Fusion Middleware32
Oracle Spatial Studio20
Oracle HealthCare Applications20
Oracle Application Express10
Oracle Autonomous Health Framework11
Oracle Essbase11
Oracle GoldenGate11
Oracle Graph Server and Client11
Oracle Commerce10
Oracle Enterprise Manager11

Solution

Customers are advised to apply all relevant patches in this quarter’s CPU. Please refer to the July 2025 advisory for full details.

Identifying affected systems

A list of Tenable plugins to identify these vulnerabilities will appear here as they’re released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.

Get more information

Join Tenable's Research Special Operations (RSO) Team on the Tenable Community.
Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.


Research Special Operations

Research Special Operations

The Research Special Operations (RSO) team serves as Tenable’s Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now. Uniting the missions of the Tenable Security Response, Zero-Day Research, and Decision Science Operations teams, RSO disseminates timely, accurate, and actionable information about the latest threats and exposures.

Cybersecurity news you can use

Enter your email and never miss timely alerts and security guidance from the experts at Tenable.


文章来源: https://www.tenable.com/blog/oracle-july-2025-critical-patch-update-addresses-165-cves
如有侵权请联系:admin#unsafe.sh