National Cyber Warfare Foundation (NCWF)

Oracle October 2025 Critical Patch Update Addresses 170 CVEs


0 user ratings
2025-10-22 04:24:11
milo
Blue Team (CND)

Oracle addresses 170 CVEs in its final quarterly update of 2025 with 374 patches, including 40 critical updates.


Background


On October 21, Oracle released its Critical Patch Update (CPU) for October 2025, the fourth and final quarterly update of the year. This CPU contains fixes for 170 unique CVEs in 374 security updates across 29 Oracle product families. Out of the 374 security updates published this quarter, 10.7% of patches were assigned a critical severity. Medium severity patches accounted for the bulk of security patches at 46.3%, followed by high severity patches at 39.0%.


A donut chart illustrating the Oracle Critical Patch Update for October 2025. It shows that out of a total of 374 security patches, 146 are rated High severity, 173 are Medium, 15 are Low, and 40 are Critical. The two highest severity categories, High and Medium, make up over 85% of the total patches.


This quarter’s update includes 40 critical patches across 12 CVEs.






































SeverityIssues PatchedCVEs
Critical4012
High14657
Medium17391
Low1510
Total374170


Analysis


This quarter, the Oracle TimesTen In-Memory Database product family contained the highest number of patches at 73, accounting for 19.5% of the total patches, followed by Oracle Spatial Studio at 64 patches, which accounted for 17.1% of the total patches.


A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.






























































































































































Oracle Product FamilyNumber of PatchesRemote Exploit without Auth
Oracle TimesTen In-Memory Database7347
Oracle Spatial Studio6446
Oracle Construction and Engineering3329
Oracle E-Business Suite2017
Oracle Insurance Applications187
Oracle Java SE187
Oracle JD Edwards1814
Oracle Retail Applications163
Oracle Secure Backup92
Oracle Communications Applications96
Oracle Supply Chain90
Oracle Enterprise Manager85
Oracle HealthCare Applications85
Oracle Hyperion86
Oracle MySQL88
Oracle Commerce77
Oracle Health Sciences Applications74
Oracle Database Server62
Oracle GoldenGate62
Oracle Analytics53
Oracle Hospitality Applications55
Oracle Essbase42
Oracle Communications32
Oracle Financial Services Applications31
Oracle Fusion Middleware33
Oracle Siebel CRM32
Oracle Graph Server and Client10
Oracle REST Data Services10
Oracle PeopleSoft11


Oracle E-Business Zero-Day Vulnerabilities


As part of its CPU release for October, Oracle noted the publication of two separate out-of-band Security Alerts for its E-Business Suite (EBS) to address two zero-day vulnerabilities, CVE-2025-61882 on October 4, and CVE-2025-61884 on October 11, that were exploited in the wild. For more information about these EBS zero-day vulnerabilities, please refer to our FAQ blog post, CVE-2025-61882: Frequently Asked Questions About Oracle E-Business Suite (EBS) Zero-Day and Associated Vulnerabilities.


Solution


Customers are advised to apply all relevant patches in this quarter’s CPU. Please refer to the October 2025 advisory for full details.


Identifying affected systems


A list of Tenable plugins to identify these vulnerabilities will appear here as they’re released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.


Get more information



Join Tenable's Research Special Operations (RSO) Team on Tenable Connect and engage with us in the Threat Roundtable group for further discussions on the latest cyber threats.


Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.



The post Oracle October 2025 Critical Patch Update Addresses 170 CVEs appeared first on Security Boulevard.



Research Special Operations

Source: Security Boulevard
Source Link: https://securityboulevard.com/2025/10/oracle-october-2025-critical-patch-update-addresses-170-cves/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.