This quarter's Oracle Critical Patch Update contains patches for 334 security vulnerabilities, with Oracle Communications receiving the highest number of patches.
244 of the 334 security patches provided by the October Critical Patch Update are for non-Oracle CVEs.
The security updates cover numerous product families like Oracle Database, Oracle Java SE, Oracle Financial Services Applications, etc.
Qualys has released five QIDs mentioned to cover the security vulnerabilities patched.
In Oracle Communications products, there are several critical severity vulnerabilities addressed, which a remote attacker might exploit in low-complexity network attacks.
Oracle MySQL also has critical severity vulnerabilities addressed that may be exploited without user credentials.
Oracle Fusion Middleware's patch update contains 32 security patches, with a few vulnerabilities joined to different products.
The Oracle Financial Services Applications patch includes a total of 20 security patches, with 15 vulnerabilities that a remote attacker may exploit without user credentials.
Oracle Commerce and Oracle Enterprise Manager updates include nine and seven security patches, respectively, with a few vulnerabilities that a remote attacker may exploit without user credentials.
Oracle Analytics and Oracle Systems have security patches with critical severity vulnerabilities addressed, which may be exploited without user credentials.