Oracle Releases April 2022 Critical Patch Update
Scheduled updates for multiple Oracle Products
Summary
Scheduled updates for multiple Oracle Products
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
175 products are affected. Please review the Oracle Critical Patch Update Advisory - April 2022 for more information about these affected platforms.
Threat details
Introduction
Oracle has released its Critical Patch Update for April 2022 to address 520 vulnerabilities across multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.
Note: There are over 100 Log4j vulnerabilities, some of which concern Log4Shell. Log4j versions 1.x and 2.x vulnerabilities that are addressed in this update are CVE-2019-17571, CVE-2020-9488, CVE-2021-4104, CVE-2021-44832, CVE-2022-23302, and CVE-2022-23305. Affected organisations should review the cyber alert in conjunction with the Critical Patch Update Advisory and apply any relevant updates.
Remediation advice
Affected organisations are encouraged to review the Oracle April 2022 Critical Patch Update and apply the necessary updates or workarounds.
Definitive source of threat updates
Last edited: 20 April 2022 12:24 pm