Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Oracle released its January 2022 Critical Patch Update (CPU) on January 18, 2022, adding 497 new security patches across its listed product families. That total is not a measure of how many patches any one customer needs: applicability depends on the Oracle products and versions deployed. Administrators should identify affected components in their environments and follow the corresponding Oracle patch instructions.

What Oracle’s 497-patch update includes

Oracle describes a CPU as a collection of fixes for vulnerabilities in Oracle code and third-party components included in Oracle products. The January advisory’s figure of 497 counts new security patches added in that quarterly update; it does not mean 497 vulnerabilities affect every Oracle installation. CPUs are generally cumulative, but the advisory’s count concerns patches added since the preceding CPU. Earlier advisories cover earlier fixes. Oracle’s January 2022 CPU advisory lists affected products and versions, CVEs, risk details, and product-specific patch availability and installation documentation.

The update was released on January 18, 2022, a date Oracle also confirmed in its E-Business Suite Technology announcement, published the next day.

Does the update affect your Oracle database or other products?

The headline total cannot determine whether a particular system is exposed. Check the advisory for the exact product family and version in use, then review its vulnerability entries and linked patch documents. Oracle notes that Database or Fusion Middleware vulnerabilities may also affect Fusion Applications, depending on the components and versions present in an environment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For each relevant entry, use Oracle’s risk matrix to assess the CVE and component, whether remote exploitation without authentication is indicated, the CVSS 3.1 score and attack conditions, and potential confidentiality, integrity, and availability impacts. The matrix’s protocol information also treats secure variants as affected where applicable unless it specifically identifies only the secure variant. A CVE may appear in more than one product matrix when the same vulnerability affects multiple products.

Oracle’s text version of the January 2022 risk matrices provides vulnerability-specific conditions and impacts. CERT-EU’s January 20, 2022 advisory also summarizes the update across multiple Oracle products and recommends prompt patching. Neither the overall count nor a broad severity description establishes that every listed issue applies to your system or is being exploited.

What the update means for E-Business Suite

The CPU includes 9 new security patches for Oracle E-Business Suite, a subset of the 497 total—not nine additional patches. Oracle says five of those E-Business Suite vulnerabilities may be remotely exploitable without authentication. Applicability still depends on the installed products and versions. E-Business Suite exposure can also depend on Database and Fusion Middleware versions, so administrators should check the relevant component entries and Oracle’s environment-specific patch guidance.

How to check and apply the relevant patches

  1. Inventory your environment. Record the Oracle product families, installed versions, and supporting components, including Database and Fusion Middleware where relevant.
  2. Match products and versions to the advisory. In Oracle’s January 2022 CPU, locate the affected-product entries corresponding to your deployment and review their CVEs and risk matrices.
  3. Follow the linked patch instructions. Use the product-specific patch availability document and installation documentation to confirm applicability and prerequisites for your exact version.
  4. Apply applicable patches promptly. Oracle recommends applying relevant CPU patches without delay and planning upgrades to versions that remain supported.

Oracle provides CPU patches for versions under Premier or Extended Support. Its guidance is: “Oracle therefore strongly recommends that customers remain on actively-supported versions and apply Critical Patch Update security patches without delay.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why workarounds are not a substitute for patching

In some cases, blocking network protocols or removing unnecessary privileges may reduce risk while a patch is being planned. Oracle cautions that these changes can disrupt functionality and should be tested on non-production systems first. They do not correct the underlying vulnerability; Oracle says neither approach should be considered a long-term solution.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.