Oracle Security Patch Update – 22 October 2025

Oracle released its critical patch updates for October 2025, containing 374 new security patches for multiple affected products in Oracle code and third-party components.

The addressed vulnerabilities could allow the attacker to perform various attacks, such as obtaining sensitive information, conducting denial of service attacks, performing data manipulation (update, insert, or delete access), or executing arbitrary code and gaining access to the affected systems.

Sample of the addressed vulnerabilities:

1. Oracle Marketing Takeover Vulnerability (CVE-2025-53072):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

2. Oracle Financial Services Analytical Applications Infrastructure Denial of Service Vulnerability (CVE-2025-61756):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service

Sample of the affected products:

  • Oracle Essbase.
  • Oracle Marketing.
  • Oracle Product Hub.
  • Oracle Applications Manager.
  • Oracle iStore.
  • Oracle Financial Services Analytical Applications Infrastructure.

The complete list of the affected products: Oracle Advisory – October 2025

Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Oracle Advisory – October 2025

References