Oracle has delivered its regular quarterly collection of patches: 603 in total, 318 for its own products, and another 285 for Linux code it ships. Big Red’s VP of security assurance Eric Maurice singled out one patch as worthy of particular attention: The fix addresses CVE-2025-21556, a CVSS 9.9-out-of-10-rated vulnerability in Oracle’s Agile Product Lifecycle Management (PLM) Framework which allows a low-privileged attacker with network access to compromise that tool, and through it other Oracle products. Maurice urged action because in November 2024 Oracle published an out-of-band security alert for the Agile PLM Framework. He wrote that the patch delivered on Wednesday “includes patches for this alert as well as additional patches.” Another catch-up concerns CVE-2024-45492, a flaw in the XML parsing library LibExpat that Oracle uses in several products. The flaw was tackled in August 2024 and rated 6.2 in severity, but in December was upgraded to 9.8. NIST’s page for the flaw states: “It is awaiting reanalysis which may result in further changes to the information provided.” It's probably not a major concern, as it only poses a threat on 32-bit systems under certain conditions. But it’s rated as having a low attack complexity, and the version 2.6.3 that fixed it was published in September 2024. Libraries like this can often find their way into software and be all-but forgotten. At Oracle, it’s used in products for telcos, financial services orgs, and middleware. Other fixe...
Oracle emits 603 patches, names one it wants you to worry about soon
The Register
·Iain Thomson
·Published Jan 23, 2025
·Updated
Affected Software
43 affected components
Oracle Agile Product Lifecycle Management (PLM) Framework
Oracle Agile PLM Framework
LibExpat XML parsing library=2.6.3
Oracle Communications
Oracle Financial Services
Oracle Middleware
Oracle Analytics
Apache XMLBeans
OpenSSL
SciPy
Pivotal Spring Framework
Oracle Hospitality Applications=5.6.19.20
Oracle OPERA=5.6.19.20
Oracle JD Edwards
EnterpriseOne Tools monitoring and diagnostics tool
Samba
Oracle MySQL
curl
Kerberos
Enterprise Backup
Oracle PeopleSoft
Oracle Enterprise PeopleTools=8.60
Oracle Enterprise PeopleTools=8.61
Oracle Supply Chain platform
Oracle Engineering Data Management system
Apache Xerces C++ XML parser=3.2.5
Oracle Linux
gstreamer1 plugins-base library
Oracle Agile Product Lifecycle Management (PLM) Framework=CVE-2025-21556
Oracle LibExpat>=2.6.3
Oracle OPERA>=5.6.19.20
Oracle EnterpriseOne Tools
Oracle Samba
Oracle MySQL
Oracle Enterprise PeopleTools
Oracle Apache Xerces C++ XML parser>=3.2.5
Oracle gstreamer1-plugins-base
Oracle Communications
Oracle Financial Services
Oracle Middleware
Oracle Analytics
Oracle Hospitality Applications
Oracle PeopleSoft
Frequently Asked Questions
1
What is the total number of patches released by Oracle in this update?
Oracle released a total of 603 patches in its latest update.
2
Which specific patch did Oracle's VP of security assurance highlight as particularly important?
The VP of security assurance highlighted the patch related to CVE-2025-21556 as particularly important.
3
What types of software were included in the Oracle patch release?
The patch release included updates for various Oracle products as well as Linux code.
4
Which popular XML parsing library is affected by this patch release?
The LibExpat XML parsing library is one of the affected software in this patch release.
5
How many patches were specifically released for Linux code by Oracle?
Oracle released 285 patches specifically for Linux code in this update.