Full Report
Oracle addresses 170 CVEs in its final quarterly update of 2025 with 374 patches, including 40 critical updates.BackgroundOn October 21, Oracle released its Critical Patch Update (CPU) for October 2025, the fourth and final quarterly update of the year. This CPU contains fixes for 170 unique CVEs in 374 security updates across 29 Oracle product families. Out of the 374 security updates published this quarter, 10.7% of patches were assigned a critical severity. Medium severity patches accounted for the bulk of security patches at 46.3%, followed by high severity patches at 39.0%.This quarter’s update includes 40 critical patches across 12 CVEs.SeverityIssues PatchedCVEsCritical4012High14657Medium17391Low1510Total374170AnalysisThis quarter, the Oracle TimesTen In-Memory Database product family contained the highest number of patches at 73, accounting for 19.5% of the total patches, followed by Oracle Spatial Studio at 64 patches, which accounted for 17.1% of the total patches.A full breakdown of the patches for this quarter can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.Oracle Product FamilyNumber of PatchesRemote Exploit without AuthOracle TimesTen In-Memory Database7347Oracle Spatial Studio6446Oracle Construction and Engineering3329Oracle E-Business Suite2017Oracle Insurance Applications187Oracle Java SE187Oracle JD Edwards1814Oracle Retail Applications163Oracle Secure Backup92Oracle Communications Applications96Oracle Supply Chain90Oracle Enterprise Manager85Oracle HealthCare Applications85Oracle Hyperion86Oracle MySQL88Oracle Commerce77Oracle Health Sciences Applications74Oracle Database Server62Oracle GoldenGate62Oracle Analytics53Oracle Hospitality Applications55Oracle Essbase42Oracle Communications32Oracle Financial Services Applications31Oracle Fusion Middleware33Oracle Siebel CRM32Oracle Graph Server and Client10Oracle REST Data Services10Oracle PeopleSoft11Oracle E-Business Zero-Day VulnerabilitiesAs part of its CPU release for October, Oracle noted the publication of two separate out-of-band Security Alerts for its E-Business Suite (EBS) to address two zero-day vulnerabilities, CVE-2025-61882 on October 4, and CVE-2025-61884 on October 11, that were exploited in the wild. For more information about these EBS zero-day vulnerabilities, please refer to our FAQ blog post, CVE-2025-61882: Frequently Asked Questions About Oracle E-Business Suite (EBS) Zero-Day and Associated Vulnerabilities.SolutionCustomers are advised to apply all relevant patches in this quarter’s CPU. Please refer to the October 2025 advisory for full details.Identifying affected systemsA list of Tenable plugins to identify these vulnerabilities will appear here as they’re released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.Get more informationOracle Critical Patch Update Advisory - October 2025Oracle October 2025 Critical Patch Update Risk MatricesOracle Advisory to CVE MapJoin Tenable's Research Special Operations (RSO) Team on Tenable Connect and engage with us in the Threat Roundtable group for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.
Analysis Summary
The provided article summarizes Oracle's October Critical Patch Update (CPU), which addresses 170 CVEs. Specific CVEs, individual product details, and precise scoring are not listed within the provided text snippet, but the required actions and reference points are clearly indicated.
# Vulnerability: Oracle October 2025 Critical Patch Update (170 CVEs)
## CVE Details
- CVE ID: Not individually specified in the excerpt. (The article references numerous CVEs addressed in the CPU.)
- CVSS Score: Not individually specified in the excerpt.
- CWE: Not specified in the excerpt.
## Affected Systems
- Products: Oracle Products (General coverage implied by Critical Patch Update).
- Versions: Not individually specified in the excerpt.
- Configurations: Not specified in the excerpt.
## Vulnerability Description
This is a summary of the Oracle Critical Patch Update (CPU) released in October 2025, which collectively patches 170 security vulnerabilities across various Oracle products. Specific technical details for individual vulnerabilities are contained within the official Oracle advisory.
## Exploitation
- Status: Not specified whether any of these 170 CVEs are currently exploited in the wild based on this summary.
- Complexity: Not specified.
- Attack Vector: Not specified.
## Impact
- Confidentiality: Varies by individual CVE.
- Integrity: Varies by individual CVE.
- Availability: Varies by individual CVE.
## Remediation
### Patches
- **Action:** Customers are advised to apply **all relevant patches** included in this quarter’s CPU immediately.
- **Reference:** Full details are available in the October 2025 advisory.
### Workarounds
- Workarounds are not detailed in this summary, directing users to the official advisory for comprehensive guidance.
## Detection
- **Indicators of Compromise:** Not specified.
- **Detection methods and tools:** Tenable plugins to identify these vulnerabilities will appear on their search page filtered by "(October 2025 CPU)" upon release.
## References
- Vendor Advisories:
- Oracle Critical Patch Update Advisory - October 2025 (`https://www.oracle.com/security-alerts/cpuoct2025.html`)
- Oracle October 2025 Critical Patch Update Risk Matrices (`https://www.oracle.com/security-alerts/cpuoct2025verbose.html`)
- Oracle Advisory to CVE Map (`https://www.oracle.com/security-alerts/public-vuln-to-advisory-mapping.html`)
- Relevant Links:
- Tenable plugin search for "(October 2025 CPU)" (`https://www.tenable.com/plugins/search?q=%22%28October+2025+CPU%29%22&sort=&page=1`)