Oracle has published a planned release of updates to its products (Critical Patch Update), aimed at eliminating critical issues and vulnerabilities. It is noted that the July update was the largest in history in terms of the number of vulnerabilities – 1449 security problems were fixed, affecting 334 Oracle products. The surge in the number of vulnerabilities is explained by the analysis of problems identified through the use of AI tools.
Some problems in open source Oracle projects:
- 19 security problems in Java SE. 17 vulnerabilities in Java SE can be exploited remotely without authentication and affect environments that allow execution of untrusted code. The five most dangerous problems in Java SE have a severity level of 7.5-7.8 and affect the installer, scripting, Little CMS and function libraries. The vulnerabilities have been resolved in Java SE 26.0.2, 25.0.4, 21.0.12, 17.0.29, 11.0.32, 8u492 releases.
- 41 vulnerabilities in the MySQL server, of which two have a severity level greater than 8. The most dangerous vulnerability (severity level 8.4) allows a local attack through the group replication plugin. The second vulnerability (risk level 8.2) is present in the plugin for X11 support and can be exploited remotely without authentication. New versions of MySQL Community Server with a fix have not yet been generated.
- 16 vulnerabilities in VirtualBox, six of which are marked as dangerous (danger level 7.4-7.8). Details about the nature of the vulnerabilities are not disclosed. The issues are resolved in the release
/Reports, release notes, official announcements.