Critical Patch Update di Oracle
Oracle ha rilasciato il Critical Patch Update di luglio che mira a correggere numerose vulnerabilità su più prodotti, di cui 210 con gravità “critica” e 539 con gravità “alta”.
Tipologia
- Arbitrary Code Execution
- Information Disclosure
- Authentication Bypass
- Denial of Service
- Privilege Escalation
Prodotti e/o versioni interessati
| Prodotti | |
| Oracle | Application Testing Suite Public Sector Financials (International) Cost Management Retail EFTLink Human Resources Utilities Network Management System Retail Integration Bus Enterprise Manager Base Platform Communications Pricing Design Center Product Workbench PeopleSoft Enterprise PeopleTools Siebel CRM Cloud Applications Product Hub Document Management and Collaboration Bills of Material Contracts Integration Siebel CRM Development Access Manager Net Services Database Server VM VirtualBox Data Integrator Java SE Workflow WebLogic Server GoldenGate MySQL Server Hospitality Simphony BI Publisher Payments MySQL Connectors Coherence MySQL Router Identity Manager WebCenter Content Project Costing JDeveloper Unified Directory HTTP Server Platform Security for Java Service Delivery Platform TimesTen In-Memory Database WebCenter Enterprise Capture WebCenter Content: Imaging JD Edwards EnterpriseOne CRM Foundation JD Edwards EnterpriseOne HCM Foundation JD Edwards EnterpriseOne Human Resources Management JD Edwards EnterpriseOne General Ledger JD Edwards EnterpriseOne Requirements Planning JD Edwards EnterpriseOne Advanced Pricing - Procurement JD Edwards EnterpriseOne Solution Advisor Identity Manager Connector Managed File Transfer SOA Suite Business Process Management Suite WebCenter Sites WebCenter Portal Enterprise Command Center Framework Transportation Management PeopleSoft Enterprise FIN Staffing Front Office PeopleSoft Enterprise CS Campus Community PeopleSoft Enterprise FIN Cash Management PeopleSoft Enterprise CS Student Records PeopleSoft Enterprise FIN Project Costing PeopleSoft Enterprise CS Student Financials PeopleSoft Enterprise CC Common Application Objects JD Edwards EnterpriseOne Procurement and Subcontract Management JD Edwards EnterpriseOne Tools Solaris PeopleSoft Enterprise HCM Global Payroll Switzerland PeopleSoft Enterprise HCM Human Resources Applications Technology Stack Business Intelligence Enterprise Edition Applications Framework Common Application Components General Ledger Process Manufacturing Regulatory Management U.S. Federal Financials Content Manager Enterprise Asset Management Universal Work Queue Interaction Blending Process Manufacturing Inventory Process Manufacturing Financials EDI Gateway Price Protection iReceivables Trading Community Sales Offline E-Business Intelligence Installed Base Field Service Cash Management Assets Payroll Applications Manager Financials Common Modules Application Object Library Complex Maintenance, Repair and Overhaul Receivables TeleSales Compensation Workbench Supply Chain Trading Connector iStore iSupport Advanced Outbound Telephony HCM Common Architecture Demand Signal Repository Customer Support Mobile Application Server Project Contracts Lease and Finance Management Quality Quoting Advanced Pricing Risk Management Order Management Trade Management Work in Process Warehouse Management HCM Configuration Workbench Project Intelligence Property Manager Inventory Management Shipping Execution Customer Care Capacity Public Sector Payroll Public Sector Financials Labor Distribution Service Fulfillment Manager Learning Management Time and Labor Transportation Execution Telecommunications Billing Integrator SDP Number Portability Treasury HRMS (France) Public Sector Human Resources E-Business Tax Scripting US Federal Human Resources Project Portfolio Analysis Advanced Collections Process Manufacturing Systems Landed Cost Management Process Manufacturing Logistics Customers Online iRecruitment Process Manufacturing Product Development Financials Common Country Financials for the Americas Loans Advanced Supply Chain Planning Demantra Demand Management Production Scheduling Communications BRM - Elastic Charging Engine PeopleSoft Enterprise SCM Order Management PeopleSoft Enterprise SCM Supplier Contract Management PeopleSoft Enterprise FIN Billing Argentina PeopleSoft Enterprise FIN Staffing Front Office Brazil PeopleSoft Enterprise FIN Common Objects Brazil PeopleSoft Enterprise HCM Talent Acquisition Manager PeopleSoft Enterprise SCM Mobile Inventory Management PeopleSoft Enterprise SCM Inventory PeopleSoft Enterprise FIN Payables PeopleSoft Enterprise SCM Manufacturing Project Foundation Communications Billing and Revenue Management Communications Unified Inventory Management Banking Trade Finance Process Management MES for Process Manufacturing Banking Trade Finance Applications DBA HRMS (UK) HRMS (US) Configure to Order Communications Service Catalog and Design Commerce Platform Advanced Benefits Commerce Guided Search / Commerce Experience Manager Commerce Guided Search Platform Services Agile PLM Product Lifecycle Analytics Agile Product Lifecycle Management for Process Agile Engineering Data Management PeopleSoft Enterprise CRM Common Objects PeopleSoft Enterprise FIN Expenses PeopleSoft Enterprise FIN Program Management PeopleSoft Enterprise SCM Purchasing PeopleSoft Enterprise SCM eProcurement PeopleSoft In-Memory Project Discovery E-Business Suite Secure Enterprise Search Communications Converged Application Server PeopleSoft Enterprise FIN Common Objects Argentina PeopleSoft Enterprise FIN Manufacturing Argentina PeopleSoft Enterprise FIN Manufacturing Brazil In-Memory Cost Management for Discrete Industries Payables Purchasing Process Manufacturing Process Execution Yard Management Flow Manufacturing Advanced Planning Command Center HRMS (Norway) |
Misure correttive
In linea con le dichiarazioni del vendor, si consiglia di aggiornare i prodotti all’ultima versione disponibile.
Per approfondimenti sui prodotti interessati e sulle modalità di intervento si consiglia di fare riferimento al bollettino di sicurezza disponibile nella sezione Riferimenti.
CVE
In allegato sono riportate le sole CVE relative alle vulnerabilità con gravità “critica” e “alta”
Riferimenti
- https://www.oracle.com/security-alerts/cpujul2026.html:
- https://www.acn.gov.it/portale/w/critical-patch-update-di-oracle-9
SOC
Documenti da scaricare
- cve.csv » [XLS 18 kB]
Altri comunicati stampa di questa categoria
- Campagna di smishing a tema Trenitalia (23/07/2026, 14:00)
- Nuova campagna ClickFix usa ingegneria sociale per diffondere malware tramite prompt ingannevoli (19/02/2026, 23:00)
- Microsoft corregge una vulnerabilità ad alta gravità in Windows Admin Center che consente l’elevazione di privilegi (19/02/2026, 23:00)

![[external Link]: Dipartimento per la trasformazione digitale](https://assets-eu-01.kc-usercontent.com:443/505985a0-ced9-0184-5d3c-36be71e24187/89d3384e-8482-4aa1-8ae3-05b637cd88dc/dipartimento-transformazione-digitale.jpg?w=568&h=150&fit=crop&crop=smart&fm=webp&lossless=0&q=75)
![[external Link]: ACN](https://assets-eu-01.kc-usercontent.com:443/505985a0-ced9-0184-5d3c-36be71e24187/ac0e1861-4b7f-4ba1-85de-2e7e39b5372f/acn.jpg?w=568&h=150&fit=crop&crop=smart&fm=webp&lossless=0&q=75)
![[external Link]: Siag](https://assets-eu-01.kc-usercontent.com:443/505985a0-ced9-0184-5d3c-36be71e24187/dd32e81c-8456-4c46-803a-21a6983881c3/siag.jpg?w=568&h=150&fit=crop&crop=smart&fm=webp&lossless=0&q=75)