Oracle April 2021 Critical Patch Update for All Product Families

Oracle April 2021 Critical Patch Update for All Product Families

May 17, 2021 | Jie Ji

Vulnerability Description

On April 21, 2021, NSFOCUS detected that Oracle released the April 2021 Critical Patch Update (CPU), which fixed 400 vulnerabilities of varying risk levels. This CPU involves multiple commonly used products, such as Oracle Database Server, Oracle Java SE, Oracle Fusion Middleware, Oracle MySQL, and Oracle Communications. Oracle strongly recommends users fix these vulnerabilities by applying Critical Patch Update patches as soon as possible.

Reference link:

https://www.oracle.com/security-alerts/cpuapr2021.html

Description of Critical Vulnerabilities

Based on the product popularity and vulnerability importance, we have selected the vulnerabilities with a huge impact from the updates for affected users.

Oracle MySQL multiple vulnerabilities:

This CPU contains 49 security patches for Oracle MySQL. Nine of these vulnerabilities may be remotely exploitable without requiring user credentials. The CVE IDs of these vulnerabilities are listed as follows:

CVE-2020-17527

CVE-2020-17530

CVE-2020-1971

CVE-2020-28196

CVE-2020-8277

CVE-2021-2307

CVE-2021-23841

CVE-2021-3449

CVE-2021-3450

Oracle Communications Applications multiple vulnerabilities:

This CPU contains 13 security patches for Oracle Communications Applications. 12 of these vulnerabilities may be remotely exploitable without requiring user credentials. The CVE IDs of high-risk vulnerabilities are listed as follows:

CVE-2020-11612

CVE-2019-0228

CVE-2020-28052

Oracle E-Business Suite multiple vulnerabilities:

This CPU contains 70 security patches for Oracle E-Business Suite. 22 of these vulnerabilities may be remotely exploitable without requiring user credentials. Attackers could gain network access via HTTP to compromise products in Oracle E-Business Suite, resulting in unauthorized creation access to critical data or complete access to accessible data of all products. The CVE IDs of high-risk vulnerabilities are listed as follows:

CVE-2021-2200

CVE-2021-2205

Oracle Virtualization multiple vulnerabilities:

This CPU contains 24 security patches for Oracle Virtualization. Five of these vulnerabilities may be remotely exploitable without requiring user credentials. The CVE IDs of high-risk vulnerabilities are listed as follows:

CVE-2021-2177

CVE-2021-2221

CVE-2021-2248

Oracle Fusion Middleware multiple vulnerabilities:

This CPU contains 45 security patches for Oracle Fusion Middleware. 36 of these vulnerabilities may be remotely exploitable without requiring user credentials. The CVE IDs of high-risk vulnerabilities are listed as follows:

CVE-2020-9480

CVE-2020-10683

CVE-2021-2302

CVE-2020-11612

CVE-2021-2136

CVE-2021-2135

Oracle Retail Applications multiple vulnerabilities:

This CPU contains 35 security patches for Oracle Retail Applications. 31 of these vulnerabilities may be remotely exploitable without requiring user credentials. The CVE IDs of high-risk vulnerabilities are listed as follows:

CVE-2019-0228

CVE-2020-10683

Oracle April 2021 Critical Patch Update is summarized as follows:

ProductNumber of VulnerabilitiesNumber of Remote Exploits Without AuthenticationCVSS Base Score
Oracle Database Products Risk Matrices1047.5
Oracle Database Server1047.5
Oracle Global Lifecycle Management116.5
Oracle NoSQL Database437.5
Oracle REST Data Services115.3
Oracle Spatial Studio215.3
Oracle SQL Developer117.5
Oracle Commerce447.5
Oracle Communications Applications13129.8
Oracle Communications2299.8
Oracle Construction and Engineering869.8
Oracle E-Business Suite70229.1
Oracle Enterprise Manager989.8
Oracle Financial Services Applications15109.8
Oracle Food and Beverage Applications217.5
Oracle Fusion Middleware45369.8
Oracle Health Sciences Applications339.1
Oracle Hospitality Applications649.8
Oracle Hyperion219.6
Oracle iLearning105.5
Oracle Insurance Applications117.3
Oracle Java SE447.5
Oracle JD Edwards10109.8
Oracle MySQL49109.8
Oracle PeopleSoft18138.3
Oracle Retail Applications35319.8
Oracle Siebel CRM878.1
Oracle Storage Gateway6210
Oracle Supply Chain559.8
Oracle Support Tools104.9
Oracle Systems5110
Oracle Utilities Applications559.8
Oracle Virtualization24510

Statement

This advisory is only used to describe a potential risk. NSFOCUS does not provide any commitment or promise on this advisory. NSFOCUS and the author will not bear any liability for any direct and/or indirect consequences and losses caused by transmitting and/or using this advisory. NSFOCUS reserves all the rights to modify and interpret this advisory. Please include this statement paragraph when reproducing or transferring this advisory. Do not modify this advisory, add/delete any information to/from it, or use this advisory for commercial purposes without permission from NSFOCUS.