Oracle has released its January 2025 Critical Patch Update (CPU), addressing 318 security vulnerabilities across its product portfolio. The most critical vulnerability identified is in the Oracle Agile Product Lifecycle Management (PLM) Framework (CVE-2025-21556), carrying a severe CVSS score of 9.9. This flaw could potentially allow attackers to gain control of vulnerable systems through HTTP network access.
Key Vulnerabilities Addressed:
– Oracle Agile PLM Framework (CVE-2025-21556) – CVSS 9.9
– Multiple Critical Flaws (CVSS 9.8) affecting:
– JD Edwards EnterpriseOne Tools
– Oracle Communications systems
– Oracle WebLogic Server
– Oracle BI Publisher
– Oracle Business Intelligence Enterprise Edition
Notable Security Concerns:
– Active exploitation attempts were previously detected against CVE-2024-21287
– Oracle WebLogic Server vulnerability (CVE-2025-21535) shares similarities with the actively exploited CVE-2020-2883
– A critical Kerberos 5 flaw (CVE-2024-37371) affecting Communications Billing and Revenue Management
Additional Updates:
– 285 new security patches for Oracle Linux
– Updates for various communication and business intelligence platforms
Oracle strongly recommends customers to immediately apply these security updates to protect their systems from potential exploitation.
