Post #4039203
2026-07-23 15:18 UTC
Oracle had a whopping 1,434 unique CVEs across 334 products, many of them likely for years lying around in their closed-source super-secret enterprise grade software you should totally keep on buying from them.
Oracle left gaping vulnerabilities in products such as Database Server, APEX, Autonomous Health Framework, Essbase, Global Lifecycle Management, GoldenGate, NoSQL Database, Spatial Studio, SQL Developer, TimesTen In-Memory Database, Application Testing Suite, Commerce, Communications, Construction and Engineering, and E-Business Suite.
Also vulnerable for ages were Enterprise Manager, Financial Services Applications, Food and Beverage Applications, Fusion Middleware, Analytics, HealthCare Applications, Hospitality Applications, Java SE, JD Edwards, MySQL, PeopleSoft, Retail Applications, Siebel CRM, Supply Chain, Systems, Utilities Applications, and Virtualization.
Oracle would like to have you know that NDA’s are really good for security.
https://www.securityweek.com/oracle-patches-over-1400-vulnerabilities-with-quarterly-security-updates/
Replies (1)
-
@stiiin@infosec.space 2026-07-23 16:14
@avuko@infosec.exchange 60 hits on the term "Log4j" in the advisory. These people are unserious.