Skip to main content

Oracle Releases April 2022 Critical Patch Update

Scheduled updates for multiple Oracle Products

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Scheduled updates for multiple Oracle Products


Affected platforms

The following platforms are known to be affected:

The following platforms are also known to be affected:

175 products are affected. Please review the Oracle Critical Patch Update Advisory - April 2022 for more information about these affected platforms.

Threat details

Introduction

Oracle has released its Critical Patch Update for April 2022 to address 520 vulnerabilities across multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. 

Note: There are over 100 Log4j vulnerabilities, some of which concern Log4Shell. Log4j versions 1.x and 2.x vulnerabilities that are addressed in this update are CVE-2019-17571, CVE-2020-9488, CVE-2021-4104, CVE-2021-44832, CVE-2022-23302, and CVE-2022-23305. Affected organisations should review the cyber alert in conjunction with the Critical Patch Update Advisory and apply any relevant updates.


Remediation advice

Affected organisations are encouraged to review the Oracle April 2022 Critical Patch Update and apply the necessary updates or workarounds.


Last edited: 20 April 2022 12:24 pm