Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsOracle’s Critical Patch Update (CPU) released on 19 July 2022 included 349 new security patches across the product families covered by the advisory. That is a portfolio-wide total—not 349 patches for one Oracle product and not a count of every vulnerability Oracle had ever fixed. Administrators need to check the affected-product and version matrices, then follow the relevant product documentation to confirm patch availability and installation steps.
This is a historical advisory, not a statement of the latest fixes available today. Oracle’s current advisory index lists the July 2022 CPU as Rev 4, dated 31 October 2022.
What Oracle’s 349-patch count covers
A CPU is a collection of security patches addressing multiple vulnerabilities in Oracle code and in third-party components included in Oracle products. The July 2022 total counts new patches in that advisory, across the product families it lists. Earlier CPUs remain relevant for fixes they introduced; the July matrices cover vulnerabilities newly addressed in this release.
Oracle’s figures for Oracle Database Products are a subset of the total. The advisory reports 23 new patches for Oracle Database Products, including 9 for Oracle Database Server in the server risk-matrix section. The server matrix also says one vulnerability may be remotely exploitable without authentication. Those figures describe the database subset, not the full CPU.
Recommended Free Tools
#1 Best Overall
How to identify the patches relevant to your systems
- Inventory Oracle products and versions. Record what is deployed, including the specific versions and components in use.
- Match each installation to Oracle’s risk matrices. The July 2022 risk matrices identify affected products and versions, vulnerability type, exploitation conditions, and potential impact. A CVE is a vulnerability identifier; the same CVE can appear under multiple products when that vulnerability affects more than one product.
- Assess exposure in context. Oracle scores vulnerabilities using CVSS 3.1, but a score alone is not a complete risk decision for a particular environment. Consider whether a system is network-accessible, whether exploitation requires authentication, what privileges or access are needed, the potential impact, and how your organization uses the affected product. Oracle says it does not disclose its detailed internal analysis for each vulnerability; the matrices and related documentation provide information for customers to perform their own assessment.
- Confirm support eligibility and patch instructions. Check that the version is in Premier Support or Extended Support, then consult the applicable product-specific Patch Availability Document for availability and installation directions. Oracle says CPU patches are provided for versions in those support phases; products outside them are not tested for the vulnerabilities addressed by the CPU. Oracle recommends upgrading unsupported versions so future CPU patches are available.
- Apply the applicable patches promptly. Oracle recommends applying CPU security patches without delay. Database, Fusion Middleware, and Enterprise Manager patching follows Oracle’s Software Error Correction Support Policy; consult the product-specific policy rather than assuming identical patch rules for every Oracle product.
Temporary measures before patching
If immediate patching is not possible, Oracle says risk may be reduced by blocking network protocols required for attacks or by removing unnecessary user privileges or access to packages. Either change may disrupt application functionality, so test it in a non-production environment before applying it to production. These are interim risk-reduction measures, not fixes for the underlying vulnerabilities; Oracle warns that neither approach is a long-term replacement for patching.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Advisory revisions and the separate May alert
Oracle initially released the July CPU on 19 July 2022. Its advisory history records Rev 2 on 25 July, including a WebCenter Sites Support Tools version-detail update and a credit addition; Rev 3 on 28 July, updating affected-version information for WebLogic CVE-2021-40690; and Rev 4 on 31 October, updating the credit section. The current Oracle security advisory index also lists the July 2022 advisory as Rev 4 dated 31 October 2022.
Rank #2
Oracle separately issued a Security Alert for Oracle E-Business Suite CVE-2022-21500 on 19 May 2022, after the April CPU and before the July CPU. Oracle says the July E-Business Suite CPU includes patches for that alert as well as additional patches. The May alert is distinct from the July CPU’s 349-patch total.
Quick Recap
Best Value
Rank #3
Sources
- Oracle Critical Patch Update Advisory – July 2022
- Text Form of Oracle Critical Patch Update – July 2022 Risk Matrices
- Critical Patch Updates, Security Alerts and Bulletins
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

