Critical Patch Update Announcement in April for All Oracle Products

Critical Patch Update Announcement in April for All Oracle Products

April 18, 2025 | NSFOCUS

Overview

On April 16, 2025, NSFOCUS CERT detected that Oracle officially released the Critical Patch Update (CPU) for April. A total of 390 vulnerabilities with different degrees were fixed this time. This security update involves Oracle MySQL Connectors, Oracle MySQL Server, Oracle Java SE, Oracle Fusion Middleware, Oracle Financial Services Applications, Oracle Communications Applications and many other commonly used products. Oracle strongly recommends that customers apply critical patch update fixes to fix vulnerabilities as soon as possible.

Reference link: https://www.oracle.com/security-alerts/cpuapr2025.html

Key Vulnerabilities

Oracle MySQL Connectors Memory Corruption Vulnerability (CVE-2025-30706):

A memory corruption vulnerability exists in Oracle MySQL Connectors. An attacker with ordinary user rights can take over MySQL Connectors by gaining network access through multiple protocols. The CVSS score is 7.5.

Oracle VM VirtualBox Authentication Bypass Vulnerability (CVE-2025-30712):

An authentication bypass vulnerability exists in Oracle VM VirtualBox. An unauthenticated attacker can log into the infrastructure of Oracle VM VirtualBox, thereby adding, deleting, modifying and checking all data accessible to Oracle VM VirtualBox and causing a partial denial of service. The CVSS score is 8.1.

Oracle Common Applications Authentication Bypass Vulnerability (CVE-2025-30716):

An authentication bypass vulnerability exists in Oracle Common Applications. An unauthenticated attacker can bypass Oracle Common Applications authentication by constructing an HTTP request to query all data accessible to Oracle Common Applications. The CVSS score is 7.5.

Oracle’s official April critical patch update vulnerability summary is as follows:

ProductsNumber of vulnerabilitiesNumber of unauthorized remote exploitsHighest CVSS score
Oracle Database Products Risk Matrices737.4
Oracle Database Server737.4
Oracle Application Express117.5
Oracle Autonomous Health Framework117.5
Oracle Essbase104.1
Oracle GoldenGate427.5
Oracle Graph Server and Client115.3
Oracle NoSQL Database106.7
Oracle REST Data Services106.7
Oracle Secure Backup106.7
Oracle SQL Developer227.5
Oracle TimesTen In-Memory Database227.5
Oracle Commerce659.8
Oracle Communications Applications42359.8
Oracle Communications103829.8
Oracle Construction and Engineering767.5
Oracle E-Business Suite16119.8
Oracle Enterprise Manager449.8
Oracle Financial Services Applications34229.8
Oracle Food and Beverage Applications327.6
Oracle Fusion Middleware31269.8
Oracle Analytics15119.8
Oracle Hospitality Applications329.8
Oracle Hyperion329.1
Oracle Insurance Applications117.5
Oracle Java SE657.7
Oracle JD Edwards859.8
Oracle MySQL4329.1
Oracle PeopleSoft418.1
Oracle Policy Automation337.5
Oracle Retail Applications11119.8
Oracle Siebel CRM427.5

Mitigation

Patch update

Please refer to the appendix “Affected Products and Patch Information” of this article to download the affected product update patch in time, and refer to the readme file in the patch installation package for installation and update to ensure long-term effective protection.

Note: Oracle official patches require users to hold a license account for genuine software. After logging into https://support.oracle.com with this account, you can download the latest patches.

WebLogic temporary protection measures

1. Restrict T3 protocol access

If the relevant users are temporarily unable to install patches or do not communicate with JVM through the T3 protocol, the following measures can be used to block attacks that exploit T3 protocol vulnerabilities:

WebLogic Server provides a default connection filter named weblogic.security.net.ConnectionFilterImpl, which accepts all incoming connections and can be used to configure rules for access control of T3 and T3s protocols. The detailed steps are as follows:

  1. Enter the WebLogic console, in the configuration page of base_domain, enter the “Security” tab page, click “Filter”, and enter the connection filter configuration.
  2. Enter: weblogic.security.net.ConnectionFilterImpl in the connection filter, refer to the following writing method, and configure rules that meet the actual situation of the enterprise in the connection filter rules:

127.0.0.1 * * allow t3 t3s

Local IP ** allow t3 t3s

IP address allowed to access * * allow t3 t3s* * * deny t3 t3s

The format of the connection filter rule is as follows: target localAddress localPort action protocols, where:

  • Target specifies one or more servers to be filtered.
  • LocalAddress can define the host address of the server. (If an asterisk (*) is specified, the match returned will be all local IP addresses.)
  • LocalPort defines the port that the server is listening on. (If an asterisk is specified, the result returned by matching will be all available ports on the server).
  • Action specifies the action to be performed. (The value must be “allow” or “deny”.)

Protocols is a list of protocol names to be matched. (One of the following protocols must be specified: http, https, t3, t3s, giop, giops, dcom or ftp. ) If no protocol is defined, all protocols will match one rule.

  1. If the rule does not take effect after saving, it is recommended to restart the WebLogic service (restarting the WebLogic service will cause business interruption. It is recommended that relevant personnel assess the risk before operating). Taking the Windows environment as an example, the steps to restart the service are as follows:

Enter the bin directory under the domain directory, run the stopWebLogic.cmd file in the Windows system to terminate the weblogic service, and run the stopWebLogic.sh file in the Linux system.

  1. After the termination script is executed, run the startWebLogic.cmd or startWebLogic.sh file to start WebLogic to complete the restart of the WebLogic service. Reference link: https://docs.oracle.com/cd/E24329_01/web.1211/e24485/con_filtr.htm#SCPRG377

2. Disable IIOP protocol

Users can block attacks that exploit IIOP protocol vulnerabilities by disabling the IIOP protocol. The operations are as follows:

In the WebLogic console, select “Service” -> “AdminServer” -> “Protocol”, and uncheck “Enable IIOP”. And restart the WebLogic project to make the configuration effective.

Appendix: Affected Products and Patch Information

Affected Products and Version No.Available patches
Autonomous Health Framework, versions 23.8.0-23.11.0, 24.1.0-24.11.0, 25.1.0, 25.2.0https://support.oracle.com/rs?type=doc&id=3070732.1
GoldenGate Stream Analytics, versions 19.1.0.0.0-19.1.0.0.10https://support.oracle.com/rs?type=doc&id=3070732.1
JD Edwards EnterpriseOne Tools, versions 9.2.0.0-9.2.9.2https://support.oracle.com/rs?type=doc&id=3078792.1
Management Cloud Engine, version 24.3.0https://support.oracle.com/rs?type=doc&id=3079189.1
MySQL Client, versions 8.0.0-8.0.41, 8.4.0-8.4.4, 9.0.0-9.2.0https://support.oracle.com/rs?type=doc&id=3078827.1
MySQL Cluster, versions 7.6.0-7.6.33, 8.0.0-8.0.41, 8.4.0-8.4.4, 9.0.0-9.2.0https://support.oracle.com/rs?type=doc&id=3078827.1
MySQL Connectors, versions 9.0.0-9.2.0https://support.oracle.com/rs?type=doc&id=3078827.1
MySQL Enterprise Backup, versions 8.0.0-8.0.41, 8.4.0-8.4.4, 9.0.0-9.2.0https://support.oracle.com/rs?type=doc&id=3078827.1
MySQL Server, versions 8.0.0-8.0.41, 8.4.0-8.4.4, 9.0.0-9.2.0https://support.oracle.com/rs?type=doc&id=3078827.1
MySQL Shell, versions 8.0.32-8.0.41, 8.4.0-8.4.4, 9.0.0-9.2.0https://support.oracle.com/rs?type=doc&id=3078827.1
MySQL Workbench, versions 8.0.0-8.0.41https://support.oracle.com/rs?type=doc&id=3078827.1
Oracle Access Manager, version 12.2.1.4.0https://support.oracle.com/rs?type=doc&id=3078819.2
Oracle Agile Engineering Data Management, version 6.2.1https://support.oracle.com/rs?type=doc&id=3078833.1
Oracle Application Express, versions 23.2.15, 23.2.16, 24.1.9, 24.1.10, 24.2.3, 24.2.4https://support.oracle.com/rs?type=doc&id=3070732.1
Oracle Application Testing Suite, version 13.3.0.1https://support.oracle.com/rs?type=doc&id=3070733.1
Oracle Banking APIs, versions 21.1.0.0.0, 22.1.0.0.0, 22.2.0.0.0https://support.oracle.com
Oracle Banking Corporate Lending Process Management, versions 14.5.0.0.0-14.7.0.0.0https://support.oracle.com
Oracle Banking Digital Experience, versions 21.1.0.0.0, 22.1.0.0.0, 22.2.0.0.0https://support.oracle.com
Oracle Banking Liquidity Management, version 14.7.0.7.0https://support.oracle.com
Oracle Banking Origination, versions 14.5.0.0.0-14.7.0.0.0https://support.oracle.com
Oracle BI Publisher, versions 7.6.0.0.0, 12.2.1.4.0https://support.oracle.com/rs?type=doc&id=3078843.2
Oracle Business Activity Monitoring, version 14.1.2.0.0https://support.oracle.com/rs?type=doc&id=3078819.2
Oracle Business Intelligence Enterprise Edition, versions 7.6.0.0.0, 12.2.1.4.0https://support.oracle.com/rs?type=doc&id=3078843.2
Oracle Business Process Management Suite, versions 12.2.1.4.0, 14.1.2.0.0https://support.oracle.com/rs?type=doc&id=3078819.2
Oracle Coherence, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0https://support.oracle.com/rs?type=doc&id=3078819.2
Oracle Commerce Guided Search, versions 11.3.2, 11.4.0https://support.oracle.com/rs?type=doc&id=3078810.1
Oracle Commerce Merchandising, versions 11.3.0, 11.3.1, 11.3.2https://support.oracle.com/rs?type=doc&id=3078810.1
Oracle Commerce Platform, versions 11.3.0, 11.3.1, 11.3.2, 11.4.0https://support.oracle.com/rs?type=doc&id=3078810.1
Oracle Communications Billing and Revenue Management, versions 12.0.0.4.0-12.0.0.8.0, 15.0.0.0.0-15.0.1.0.0https://support.oracle.com/rs?type=doc&id=3077261.1
Oracle Communications Cloud Native Core Binding Support Function, versions 24.2.0-24.2.2https://support.oracle.com/rs?type=doc&id=3079188.1
Oracle Communications Cloud Native Core Certificate Management, version 24.2.2https://support.oracle.com/rs?type=doc&id=3079190.1
Oracle Communications Cloud Native Core Console, version 24.2.2https://support.oracle.com/rs?type=doc&id=3079221.1
Oracle Communications Cloud Native Core DBTier, versions 24.2.3, 24.2.4, 24.3.0https://support.oracle.com/rs?type=doc&id=3079219.1
Oracle Communications Cloud Native Core Network Data Analytics Function, version 24.2.0https://support.oracle.com/rs?type=doc&id=3079218.1
Oracle Communications Cloud Native Core Network Function Cloud Native Environment, versions 24.2.5, 25.1.100https://support.oracle.com/rs?type=doc&id=3079223.1
Oracle Communications Cloud Native Core Network Repository Function, version 24.2.3https://support.oracle.com/rs?type=doc&id=3079214.1
Oracle Communications Cloud Native Core Policy, versions 24.2.0-24.2.4https://support.oracle.com/rs?type=doc&id=3079229.1
Oracle Communications Cloud Native Core Security Edge Protection Proxy, versions 24.2.2, 24.2.3, 24.3.0https://support.oracle.com/rs?type=doc&id=3079228.1
Oracle Communications Cloud Native Core Service Communication Proxy, versions 24.2.0, 24.2.3, 24.3.0, 25.1.100https://support.oracle.com/rs?type=doc&id=3079192.1
Oracle Communications Cloud Native Core Unified Data Repository, versions 22.4.0, 23.1.0-23.4.0, 24.2.3, 25.1.100https://support.oracle.com/rs?type=doc&id=3079232.1
Oracle Communications Diameter Signaling Router, version 9.0.0.0https://support.oracle.com/rs?type=doc&id=3079132.1
Oracle Communications EAGLE Element Management System, version 46.6https://support.oracle.com/rs?type=doc&id=3079131.1
Oracle Communications Element Manager, versions 9.0.0-9.0.3https://support.oracle.com/rs?type=doc&id=3079195.1
Oracle Communications Messaging Server, version 8.1.0.26.0https://support.oracle.com/rs?type=doc&id=3077282.1
Oracle Communications MetaSolv Solution, version 6.3.1https://support.oracle.com/rs?type=doc&id=3077305.1
Oracle Communications Network Analytics Data Director, versions 24.1.0-24.3.0https://support.oracle.com/rs?type=doc&id=3079231.1
Oracle Communications Network Charging and Control, versions 12.0.6.0.0, 15.0.0.0.0, 15.0.1.0.0https://support.oracle.com/rs?type=doc&id=3078762.1
Oracle Communications Network Integrity, versions 7.3.6, 7.4.0, 7.5.0https://support.oracle.com/rs?type=doc&id=3077281.1
Oracle Communications Operations Monitor, version 5.2https://support.oracle.com/rs?type=doc&id=3080353.1
Oracle Communications Order and Service Management, versions 7.4.0, 7.4.1, 7.5.0https://support.oracle.com/rs?type=doc&id=3077292.1
Oracle Communications Policy Management, version 15.0.0.0.0https://support.oracle.com/rs?type=doc&id=3079225.1
Oracle Communications Pricing Design Center, versions 12.0.0.4.0-12.0.0.8.0, 15.0.0.0.0, 15.0.1.0.0https://support.oracle.com/rs?type=doc&id=3077300.1
Oracle Communications Service Catalog and Design, versions 8.0.0.4.0, 8.1.0.2.0https://support.oracle.com/rs?type=doc&id=3077306.1
Oracle Communications Session Border Controller, versions 9.2.0, 9.3.0, 10.0.0https://support.oracle.com/rs?type=doc&id=3079324.1
Oracle Communications Session Report Manager, versions 9.0.0-9.0.3https://support.oracle.com/rs?type=doc&id=3079216.1
Oracle Communications Unified Assurance, versions 6.0-6.1https://support.oracle.com/rs?type=doc&id=3077267.1
Oracle Communications Unified Inventory Management, versions 7.4.0-7.4.2, 7.5.0-7.5.1, 7.6.0, 7.7.0https://support.oracle.com/rs?type=doc&id=3077278.1
Oracle Communications User Data Repository, versions 14.0.0, 15.0.0, 15.0.1, 15.0.2https://support.oracle.com/rs?type=doc&id=3079130.1
Oracle Data Integrator, version 12.2.1.4.0https://support.oracle.com/rs?type=doc&id=3078819.2
Oracle Database Server, versions 19.3-19.26, 21.3-21.17, 23.4-23.7https://support.oracle.com/rs?type=doc&id=3070732.1
Oracle Demantra Demand Management, versions 12.2.6-12.2.14https://support.oracle.com/rs?type=doc&id=3078833.1
Oracle Documaker, versions 12.7.1.6, 12.7.2.3, 13.0.0.1https://support.oracle.com/rs?type=doc&id=3079097.1
Oracle E-Business Suite, versions 12.2.3-12.2.14, [ECC] 12-13https://support.oracle.com/rs?type=doc&id=2484000.1
Oracle Enterprise Communications Broker, versions 4.1.0, 4.2.0https://support.oracle.com/rs?type=doc&id=3079302.1
Oracle Enterprise Manager Base Platform, versions 13.5.0.0.0, 24.1.0.0.0https://support.oracle.com/rs?type=doc&id=3070733.1
Oracle Essbase, version 21.7.1.0.0https://support.oracle.com/rs?type=doc&id=3070732.1
Oracle Financial Services Analytical Applications Infrastructure, versions 8.0.7.8, 8.0.8.6, 8.1.1.4, 8.1.2.5https://support.oracle.com/rs?type=doc&id=3079096.1
Oracle Financial Services Behavior Detection Platform, versions 8.0.8.1, 8.1.2.8, 8.1.2.9https://support.oracle.com/rs?type=doc&id=3078941.1
Oracle Financial Services Compliance Studio, version 8.1.2.9https://support.oracle.com/rs?type=doc&id=3078903.1
Oracle Financial Services Model Management and Governance, version 8.1.2.7.0https://support.oracle.com/rs?type=doc&id=3078931.1
Oracle Financial Services Revenue Management and Billing, versions 2.9.0.0.0-7.0.0.0.0https://support.oracle.com/rs?type=doc&id=3077979.1
Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition, version 8.0.8https://support.oracle.com/rs?type=doc&id=3078942.1
Oracle Fusion Middleware MapViewer, version 12.2.1.4.0https://support.oracle.com/rs?type=doc&id=3078819.2
Oracle GoldenGate, versions 19.1.0.0.0-19.26.0.0.250219, 21.3-21.17, 23.4-23.7https://support.oracle.com/rs?type=doc&id=3070732.1
Oracle GoldenGate Veridata, versions 12.2.1.4.0-12.2.1.4.241210https://support.oracle.com/rs?type=doc&id=3070732.1
Oracle GraalVM Enterprise Edition, versions 20.3.17, 21.3.13https://support.oracle.com/rs?type=doc&id=3047853.1
Oracle GraalVM for JDK, versions 17.0.14, 21.0.6, 24https://support.oracle.com/rs?type=doc&id=3047853.1
Oracle Graph Server and Client, versions 23.4.3, 23.4.4, 24.3.0, 24.4.0https://support.oracle.com/rs?type=doc&id=3070732.1
Oracle Hospitality Cruise Shipboard Property Management System, version 23.2.1https://support.oracle.com/rs?type=doc&id=3078677.1
Oracle Hospitality Reporting and Analytics, versions 9.1.34-9.1.36https://support.oracle.com/rs?type=doc&id=3050828.1
Oracle Hospitality Simphony, versions 19.1-19.7https://support.oracle.com/rs?type=doc&id=3075400.1
Oracle HTTP Server, versions 12.2.1.4.0, 14.1.2.0.0https://support.oracle.com/rs?type=doc&id=3078819.2
Oracle Hyperion Financial Reporting, version 11.2.19.0.0https://support.oracle.com/rs?type=doc&id=2775466.2
Oracle Hyperion Infrastructure Technology, version 11.2.19.0.0https://support.oracle.com/rs?type=doc&id=2775466.2
Oracle Java SE, versions 8u441, 8u441-perf, 11.0.26, 17.0.14, 21.0.6, 24https://support.oracle.com/rs?type=doc&id=3047853.1
Oracle JDeveloper, version 12.2.1.4.0https://support.oracle.com/rs?type=doc&id=3078819.2
Oracle Managed File Transfer, versions 12.2.1.4.0, 14.1.2.0.0https://support.oracle.com/rs?type=doc&id=3078819.2
Oracle NoSQL Database, versions 1.5.0, 1.6.0, 1.6.1https://support.oracle.com/rs?type=doc&id=3070732.1
Oracle Outside In Technology, version 8.5.7https://support.oracle.com/rs?type=doc&id=3078819.2
Oracle Policy Automation, versions 12.2.0-12.2.36https://support.oracle.com/rs?type=doc&id=3078527.1
Oracle Policy Modeling, versions 12.2.0-12.2.36https://support.oracle.com/rs?type=doc&id=3078527.1
Oracle REST Data Services, versions 23.1, 23.2, 23.3, 23.4https://support.oracle.com/rs?type=doc&id=3070732.1
Oracle Retail Order Broker, version 19.1https://support.oracle.com/rs?type=doc&id=3077277.1
Oracle Retail Store Inventory Management, version 16.0.3.16https://support.oracle.com/rs?type=doc&id=3077277.1
Oracle Retail Xstore Point of Service, versions 19.0.6, 20.0.5, 21.0.4, 22.0.2, 23.0.2, 24.0.1https://support.oracle.com/rs?type=doc&id=3077277.1
Oracle SD-WAN Aware, version 9.0.1.11https://support.oracle.com/rs?type=doc&id=3079194.1
Oracle SD-WAN Edge, version 9.1.1.9https://support.oracle.com/rs?type=doc&id=3079193.1
Oracle Secure Backup, versions 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1, 18.1.0.2, 19.1.0.0https://support.oracle.com/rs?type=doc&id=3070732.1
Oracle Service Bus, version 12.2.1.4.0https://support.oracle.com/rs?type=doc&id=3078819.2
Oracle Smart View for Office, version 24.200https://support.oracle.com/rs?type=doc&id=2775466.2
Oracle SOA Suite, versions 12.2.1.4.0, 14.1.2.0.0https://support.oracle.com/rs?type=doc&id=3078819.2
Oracle Solaris, version 11https://support.oracle.com/rs?type=doc&id=3078936.1
Oracle SQL Developer, version 24.3.1.347.1826https://support.oracle.com/rs?type=doc&id=3070732.1
Oracle TimesTen In-Memory Database, versions 22.1.1.1.0-22.1.1.30.0https://support.oracle.com/rs?type=doc&id=3070732.1
Oracle Utilities Application Framework, versions 4.3.0.3.0-4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 24.1.0.0.0-24.3.0.0.0https://support.oracle.com/rs?type=doc&id=3078835.1
Oracle VM VirtualBox, version 7.1.6https://support.oracle.com/rs?type=doc&id=3078858.1
Oracle WebCenter Forms Recognition, version 14.1.1.0.0https://support.oracle.com/rs?type=doc&id=3078819.2
Oracle WebCenter Portal, version 12.2.1.4.0https://support.oracle.com/rs?type=doc&id=3078819.2
Oracle WebLogic Server, versions 12.2.1.4.0, 14.1.1.0.0https://support.oracle.com/rs?type=doc&id=3078819.2
OSS Support Tools, versions 2.11.0-2.12.46, 8.0-8.18, 18.1-18.4, 19.1-19.4, 20.1-20.4, 22.2, 23.1-23.4, 24.1-24.4, 25.1https://support.oracle.com/rs?type=doc&id=3078859.1
PeopleSoft Enterprise CC Common Application Objects, version 9.2https://support.oracle.com/rs?type=doc&id=3078811.1
PeopleSoft Enterprise HCM Talent Acquisition Manager, version 9.2https://support.oracle.com/rs?type=doc&id=3078811.1
PeopleSoft Enterprise PeopleTools, versions 8.60, 8.61, 8.62https://support.oracle.com/rs?type=doc&id=3078811.1
Primavera Gateway, versions 20.12.0-20.12.17, 21.12.0-21.12.15https://support.oracle.com/rs?type=doc&id=3078091.1
Primavera P6 Enterprise Project Portfolio Management, versions 22.12.0-22.12.18, 23.12.0-23.12.13, 24.12.0-24.12.2https://support.oracle.com/rs?type=doc&id=3078091.1
Primavera Unifier, versions 20.12.0-20.12.16, 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.13, 24.12.0-24.12.3https://support.oracle.com/rs?type=doc&id=3078091.1
Siebel Applications, versions 17.0-25.2https://support.oracle.com/rs?type=doc&id=3078812.1

Statement

This advisory is only used to describe a potential risk. NSFOCUS does not provide any commitment or promise on this advisory. NSFOCUS and the author will not bear any liability for any direct and/or indirect consequences and losses caused by transmitting and/or using this advisory. NSFOCUS reserves all the rights to modify and interpret this advisory. Please include this statement paragraph when reproducing or transferring this advisory. Do not modify this advisory, add/delete any information to/from it, or use this advisory for commercial purposes without permission from NSFOCUS.

About NSFOCUS

NSFOCUS, a pioneering leader in cybersecurity, is dedicated to safeguarding telecommunications, Internet service providers, hosting providers, and enterprises from sophisticated cyberattacks.

Founded in 2000, NSFOCUS operates globally with over 4000 employees at two headquarters in Beijing, China, and Santa Clara, CA, USA, and over 50 offices worldwide. It has a proven track record of protecting over 25% of the Fortune Global 500 companies, including four of the five largest banks and six of the world’s top ten telecommunications companies.

Leveraging technical prowess and innovation, NSFOCUS delivers a comprehensive suite of security solutions, including the Intelligent Security Operations Platform (ISOP) for modern SOC, DDoS Protection, Continuous Threat Exposure Management (CTEM) Service and Web Application and API Protection (WAAP). All the solutions and services are augmented by the Security Large Language Model (SecLLM), ML, patented algorithms and other cutting-edge research achievements developed by NSFOCUS.