Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Oracle released its April 2024 Critical Patch Update (CPU) on April 16, 2024. Oracle’s official headline figure was 441 new security patches. SecurityWeek separately counted approximately 330 unique CVEs across Oracle’s product risk matrices. Those figures are not contradictory: they measure different things.

The update affected far more than Oracle Database Server. Communications, E-Business Suite, Fusion Middleware, Financial Services Applications, Systems, Retail, PeopleSoft, Virtualization, and other Oracle product families were included. Administrators should prioritize internet-facing and remotely exploitable products, then map their exact versions to Oracle’s product-specific risk matrices and patch-availability documents.

Why the April 2024 Oracle patch totals differ

The headline “Oracle patched 330 vulnerabilities” is an oversimplification. The numbers commonly reported for this CPU represent different counting methods:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Figure What it measures Correct description
441 Oracle’s product- or component-specific security fixes Oracle’s official number of new security patches
230 A vulnerability total associated with Oracle’s CPU reporting and secondary coverage A reported vulnerability count, not a patch count
Approximately 330 SecurityWeek’s count of unique CVEs found across Oracle’s product matrices An independent cross-product CVE count

One vulnerability can require separate remediation in several Oracle products. The same CVE may therefore appear in multiple product risk matrices. Adding every product-family total would incorrectly treat repeated CVEs as separate vulnerabilities.

#1 Best Overall

Oracle’s official April 2024 CPU advisory is the authoritative source for affected versions, CVSS details, product scope, and remediation guidance. SecurityWeek’s analysis of the update explains the approximately 330-CVE figure.

Which Oracle products received the most patches?

Oracle’s product-family totals show why this was not primarily a database-only update:

Product family New patches Remote, unauthenticated issues
Oracle Communications 93 71
Oracle Fusion Middleware 51 35
Oracle Financial Services Applications 49 30
Oracle E-Business Suite 47 43
Oracle Systems 22 16
Oracle Virtualization 13 1
Oracle Enterprise Manager 11 7
Oracle Retail Applications 10 9
Oracle PeopleSoft 10 5
Oracle Commerce 8 6
Oracle Food and Beverage Applications 4 2
Oracle Utilities Applications 2 2

These figures must not be added to produce a unique vulnerability total. CVEs can be repeated across products, and Oracle’s broader product sections do not necessarily correspond one-for-one with individual CVE identifiers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What database administrators need to know

Oracle’s specific Database Server risk matrix listed eight new security patches, including three vulnerabilities remotely exploitable without authentication. The broader Oracle Database Products section listed 12 new patches because it includes related database products and components.

The Database Server fixes do not automatically apply to every Oracle client installation. Oracle specifically distinguishes server deployments from client-only installations. Administrators should check the exact release, installed options, and platform before selecting a patch.

Database exposure can also be inherited through larger applications. E-Business Suite and Enterprise Manager deployments may depend on particular Oracle Database and Fusion Middleware versions. Installing an application-specific patch without reviewing the underlying database and middleware components can leave related exposure unresolved.

E-Business Suite requires coordinated planning

Oracle E-Business Suite received 47 new patches, with 43 listed as remotely exploitable without authentication in Oracle’s matrix. That does not mean every EBS installation is exposed: the result depends on the installed release, enabled modules, network reachability, and supporting database and middleware versions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Oracle’s EBS announcement is available through its April 2024 E-Business Suite security notice. The notice references My Oracle Support Note 3007752.1. EBS administrators should treat the EBS, database, and Fusion Middleware updates as a coordinated change rather than unrelated patches.

How to prioritize the vulnerabilities

“Remote exploit without authentication” means an attacker may be able to reach the vulnerable function over a network without first providing valid credentials. It does not automatically mean that every installation is exposed to the public internet, that exploitation is confirmed, or that the issue provides remote code execution.

Prioritize using the following factors together:

  1. Network exposure: Internet-facing application, management, and administration endpoints deserve immediate attention.
  2. Authentication requirements: Remote unauthenticated issues generally deserve priority over flaws requiring local access or valid credentials.
  3. Product criticality: Focus first on systems containing financial, customer, healthcare, identity, or operational data.
  4. CVSS and impact: Review confidentiality, integrity, and availability impacts, not just the headline score.
  5. Supported versions: Unsupported releases may require an upgrade rather than a normal patch.
  6. Exploitation intelligence: Investigate credible evidence of exploitation or proof-of-concept activity separately; the CPU itself does not prove that every listed issue was actively exploited.

A high CVSS score is not a substitute for exposure analysis. A lower-scoring vulnerability on a publicly reachable management interface may deserve faster action than a higher-scoring local-only issue.

Examples of high-severity issues

The following examples illustrate the breadth of the update. They are product-specific and do not mean that every Oracle customer is affected:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
CVE Product or component Reported severity and access
CVE-2024-20997 Oracle Hospitality Simphony and Simphony Enterprise Server CVSS 9.9; remotely exploitable without authentication; versions 19.1.0–19.5.4 listed
CVE-2024-21014 Oracle Hospitality Simphony CVSS 9.8 in Oracle’s risk-matrix material
CVE-2022-46337 Apache Derby in several Oracle products CVSS 9.8 in cited matrices; product context determines exploitability
CVE-2023-46604 Apache ActiveMQ in Oracle Financial Services and related products CVSS 8.8
CVE-2023-38545 curl-related issue affecting PeopleSoft Enterprise PeopleTools CVSS 9.8; listed as remotely exploitable without authentication
CVE-2024-21112 and CVE-2024-21113 Oracle VM VirtualBox Core CVSS 8.8; locally exploitable; versions before 7.0.16 affected

Use Oracle’s verbose risk matrices for the complete CVE descriptions, affected versions, protocols, privileges, attack complexity, and impact ratings.

Third-party components and VEX statements

Oracle products bundle third-party technologies including Apache, OpenSSL, curl, PostgreSQL JDBC, Spring Security, Paramiko, and other libraries. A third-party CVE listed in an Oracle matrix does not automatically mean that the vulnerable code is exploitable in every Oracle deployment.

Oracle separately identifies some third-party vulnerabilities that are not exploitable through their inclusion in an Oracle product. Since July 2023, these entries include a VEX justification explaining why the vulnerable code cannot be controlled by an attacker or is not in the relevant execution path. Read that product-specific explanation instead of treating every listed CVE as an active vulnerability in your environment.

Administrator checklist

1. Inventory the environment

Record Oracle product families, exact releases and patch levels, operating systems, database and middleware versions, installed modules, third-party components, exposed interfaces, business dependencies, and support status.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Map installations to Oracle’s matrices

Search the official advisory by product, release, component, and CVE. Obtain the relevant Patch Availability Document through My Oracle Support, including Oracle Support Note 3000006.1. Access to patch downloads and detailed instructions may require an active Oracle Support entitlement.

3. Follow product-specific procedures

Do not copy patch commands from a news article. Oracle uses different procedures for Database Release Updates, Fusion Middleware, EBS, Java, MySQL, VirtualBox, systems products, firmware, and Oracle-managed cloud services.

4. Test a representative environment

  • Refresh or clone a representative system.
  • Test authentication, APIs, integrations, reports, batch jobs, database links, and scheduled tasks.
  • Check startup, performance, clustering, and application compatibility.
  • Validate backups, restoration, and documented rollback or recovery procedures.

5. Deploy in dependency order

A typical coordinated change may involve recovery validation, infrastructure prerequisites, database patching, middleware patching, application-tier or EBS patching, client and Java components, restarts, and service validation. The correct order depends on the deployment, so follow Oracle’s product documentation.

6. Verify and monitor

Check Oracle inventory or the product-specific patch inventory, installed versions, application availability, service logs, vulnerability-scanner results, and external exposure. Continue monitoring for authentication failures, unexpected requests, abnormal process activity, and new application errors.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If patching must be delayed

Reduce exposure temporarily by removing unnecessary internet access, restricting administrative interfaces to management networks, using firewalls or WAF rules, disabling unused components, requiring VPN or privileged-access gateways, and increasing logging and alerting. Oracle notes that blocking the network protocols required for an attack may reduce risk, but this is not a replacement for applying the appropriate patch.

Test every compensating control against business requirements. Blocking a protocol can also disable legitimate application functions.

Cloud, unsupported versions, and incomplete remediation

Patch responsibility varies. Oracle may patch some Oracle Cloud services, while customers remain responsible for customer-managed virtual machines, databases, middleware, applications, and workloads. Confirm the shared-responsibility model for the specific service.

An affected product may not receive the same fix path when it is outside active support. An upgrade to a supported release may be required. Also check systems outside the CPU’s scope: operating-system packages, standalone Java installations, separate MySQL deployments, container images, developer workstations, appliances, firmware, and third-party software.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Oracle revised the April 2024 advisory on September 18, 2024, including affected-version changes for Oracle Communications Cloud Native Core Binding Support Function and Siebel Applications. Because this is a historical CPU, confirm current support status and remediation instructions before making a change in 2026.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.