Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Oracle July 2025 Critical Patch Update Addresses 165 CVEs



A title slide announcing the Oracle Critical Patch Update for July 2025 (Q3). The slide is branded with the Tenable Research Special Operations logo and features a central yellow database icon against a background with colorful striped borders.

Oracle addresses 165 CVEs in its third quarterly update of 2025 with 309 patches, including nine critical updates.

Background

On July 15, Oracle released its Critical Patch Update (CPU) for July 2025, the third quarterly update of the year. This CPU contains fixes for 165 unique CVEs in 309 security updates across 28 Oracle product families. Out of the 309 security updates published this quarter, 2.9% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 46.6%, followed by medium severity patches at 43.7%.

A donut chart illustrating the Oracle Critical Patch Update for July 2025. It shows that out of a total of 309 security patches, 144 are rated "High" severity, 135 are "Medium", 21 are "Low", and 9 are "Critical". The two highest severity categories, High and Medium, make up over 90% of the total patches.

This quarter’s update includes nine critical patches across five CVEs.

SeverityIssues PatchedCVEs
Critical95
High14459
Medium13591
Low2110
Total309165

Analysis

This quarter, the Oracle REST Data Services product family contained the highest number of patches at 84, accounting for 27.2% of the total patches, followed by Oracle Hospitality Applications at 40 patches, which accounted for 12.9% of the total patches.

A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.

Oracle Product FamilyNumber of PatchesRemote Exploit without Auth
Oracle REST Data Services8450
Oracle Hospitality Applications403
Oracle Communications3622
Oracle NoSQL Database291
Oracle Communications Applications1813
Oracle Analytics1110
Oracle Insurance Applications118
Oracle TimesTen In-Memory Database93
Oracle JD Edwards88
Oracle Hyperion73
Oracle PeopleSoft70
Oracle Database Server60
Oracle Java SE65
Oracle MySQL65
Oracle Blockchain Platform52
Oracle Construction and Engineering52
Oracle Financial Services Applications41
Oracle E-Business Suite32
Oracle Fusion Middleware32
Oracle Spatial Studio20
Oracle HealthCare Applications20
Oracle Application Express10
Oracle Autonomous Health Framework11
Oracle Essbase11
Oracle GoldenGate11
Oracle Graph Server and Client11
Oracle Commerce10
Oracle Enterprise Manager11

Solution

Customers are advised to apply all relevant patches in this quarter’s CPU. Please refer to the July 2025 advisory for full details.

Identifying affected systems

A list of Tenable plugins to identify these vulnerabilities will appear here as they’re released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.

Get more information

Join Tenable's Research Special Operations (RSO) Team on the Tenable Community.
Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.


Cybersecurity news you can use

Enter your email and never miss timely alerts and security guidance from the experts at Tenable.