Bollettino 2026/0165

[TLP:CLEAR]

bollettino di sicurezza 2026/0165

Oracle - Critical patch update Luglio 2026

28-07-2026

oracle, fusion-middleware, missing-authentication, improper-access-control, jackson-databind, code-injection

Oracle - Critical patch update Luglio 2026

descrizione

Oracle ha rilasciato il Critical Patch Update di luglio 2026 con 1461 vulnerabilità, distribuite su un'ampia gamma di prodotti enterprise.
Dato l'elevato numero di CVE, questo bollettino si concentrerà solo su quelle con livello di rischio "critical".
Per l'elenco completo, si rimanda alla documentazione del vendor.

Il gruppo più esteso e grave riguarda componenti Oracle Fusion Middleware: Data Integrator (Rest Service), Coherence (Core), Access Manager (Authentication Engine), Unified Directory (OUD Core), WebLogic Server Proxy Plug-in, Platform Security for Java (Centralized Thirdparty Jars), Service Delivery Platform (Messaging Enabler, due istanze), WebCenter Content (Web Content Management). Queste vulnerabilità presentano CVSS 10.0 con vettore AV:N/AC:L/PR:N/UI:N/S:C, e derivano prevalentemente da autenticazione mancante su funzioni critiche o da controlli di accesso inadeguati.

Ulteriori vulnerabilità critiche (CVSS 9.8–9.9) interessano Oracle Analytics (BI Publisher), Oracle Retail Applications (Retail Integration Bus), Oracle Enterprise Manager Base Platform, Oracle Supply Chain (Agile PLM, Agile PLM for Process), Oracle PeopleSoft (FIN Common Objects Argentina e Brazil), e un componente di terze parti, FasterXML jackson-databind, tramite un gadget di deserializzazione su ibatis-sqlmap.

MySQL è interessato da vulnerabilità di controllo di accesso su Connector/Net (CVSS 8.5 e 8.1) e da un'esposizione di informazioni sensibili su MySQL Server/Cluster X Plugin (CVSS 8.2). È inoltre presente una vulnerabilità di code injection sulla libreria lodash, tramite la mancata validazione delle chiavi in _.template (CVSS 8.1).

note

Tutte le CVE presentano vettore di attacco AV:N (sfruttabili remotamente via rete) e, per la maggioranza, AC:L/PR:N/UI:N, quindi non richiedono condizioni particolari, privilegi o interazione utente.

Le vulnerabilità con CVSS 10.0 e scope Changed (S:C) su Fusion Middleware (CVE-2026-47056, CVE-2026-60217, CVE-2026-60358, CVE-2026-60360, CVE-2026-60365, CVE-2026-60366, CVE-2026-60379, CVE-2026-60389, CVE-2026-60644) hanno impatto oltre il processo corrente e coprono confidenzialità, integrità e disponibilità al massimo livello (C:H/I:H/A:H), ad eccezione di CVE-2026-60365 che non impatta la disponibilità (A:N). Queste rappresentano la priorità operativa più elevata del bollettino. Le versioni colpite comprendono le release 12.2.1.4.0 e 14.1.x di Data Integrator, Coherence (incluse 14.1.1.0.0 e 15.1.1.0.0), Access Manager, Unified Directory, Service Delivery Platform, WebCenter Content, Platform Security for Java, e le versioni 12.2.1.4.0/14.1.2.0.0/15.1.1.0.0 del WebLogic Server Proxy Plug-in.

CVE-2026-60719 (BI Publisher, Web Service API, CVSS 9.9) si distingue per PR:L (richiede autenticazione a basso privilegio) con S:C; impatta C:H/I:H/A:L. Le versioni interessate di BI Publisher sono 12.2.1.4.0, 8.2.0.0.0 e 26.01.0.0.0.

CVE-2026-61237 e CVE-2026-61239 (PeopleSoft FIN Common Objects Argentina, CVSS 9.9, S:C, PR:N) hanno profili di impatto differenziati: CVE-2026-61237 con C:H/I:L/A:L, CVE-2026-61239 con C:L/I:H/A:L. Entrambe colpiscono la versione 9.1.

CVE-2020-9547 (FasterXML jackson-databind 2.x, CVSS 9.8, S:U) riguarda la gestione errata dell'interazione tra serialization gadgets e typing tramite ibatis-sqlmap; il perimetro di prodotti Oracle impattati è ampio e include WebLogic Server, Enterprise Manager Base Platform, diverse soluzioni Communications, JD Edwards, Primavera, Retail XStore e Banking Platform. L'EPSS percentile è 0.96966, il più elevato dell'intero bollettino, indicando una probabilità di sfruttamento significativamente superiore alle altre CVE.

CVE-2026-46982 e CVE-2026-46983 (Oracle Retail Integration Bus, CWE-284, CVSS 9.8, S:U) colpiscono rispettivamente le versioni 14.1.3.2 e 16.0.3. CVE-2026-46994 (Enterprise Manager Base Platform, Agent Next Gen, CWE-284, CVSS 9.8) interessa le versioni 13.5.0.0 e 24.1.0.0.0. CVE-2026-61167 (Agile PLM 9.3.6) e CVE-2026-61183 (Agile PLM for Process 6.2.4) hanno CVSS 9.8 e S:U. CVE-2026-61233 (PeopleSoft FIN Common Objects Brazil 9.1, CVSS 9.8) e CVE-2026-60173 (BI Publisher BI Platform Security, CVSS 9.8) completano il gruppo ad alta criticità con S:U.

MySQL Connector/Net versioni 9.7.0–9.7.1 è colpito da CVE-2026-60193 (AC:H/PR:L/S:C, CVSS 8.5, CWE-284) e CVE-2026-60192 (AC:H/PR:N/S:U, CVSS 8.1, CWE-284). MySQL Server e MySQL Cluster (versioni 8.0.0–8.0.47, 8.4.0–8.4.10, 9.7.0, 9.7.1) sono colpiti da CVE-2026-60315 (X Plugin, CWE-200, CVSS 8.2, S:U, C:L/I:N/A:H).

CVE-2026-4800 riguarda code injection (CWE-94) in lodash/lodash-amd/lodash-es/lodash.template versioni 4.0.0–<4.18.0 tramite mancata validazione dei nomi delle chiavi in options.imports di _.template; il vettore è AV:N/AC:H/PR:N/UI:N/S:U con EPSS percentile 0.83497.

Non risultano a oggi CVE nel catalogo CISA KEV, exploit in the wild o proof-of-concept pubblici.

CVE

CVE CVSS EPSS priority
CVE-2020-9547 3.1: 9.8 18.671% | 96.97% 19.5/critical
CVE-2026-60217 3.1: 10.0 0.474% | 38.31% 15.9/critical
CVE-2026-60360 3.1: 10.0 0.450% | 36.75% 15.8/critical
CVE-2026-60358 3.1: 10.0 0.450% | 36.75% 15.8/critical
CVE-2026-60379 3.1: 10.0 0.450% | 36.75% 15.8/critical
CVE-2026-60389 3.1: 10.0 0.450% | 36.74% 15.8/critical
CVE-2026-4800 3.1: 8.1 2.566% | 83.50% 15.6/critical
CVE-2026-60173 3.1: 9.8 0.450% | 36.75% 15.5/critical
CVE-2026-61183 3.1: 9.8 0.450% | 36.75% 15.5/critical
CVE-2026-46983 3.1: 9.8 0.450% | 36.75% 15.5/critical
CVE-2026-61233 3.1: 9.8 0.450% | 36.75% 15.5/critical
CVE-2026-61167 3.1: 9.8 0.450% | 36.75% 15.5/critical
CVE-2026-60365 3.1: 10.0 0.377% | 30.33% 15.0/critical
CVE-2026-60719 3.1: 9.9 0.374% | 29.97% 14.8/critical
CVE-2026-60644 3.1: 10.0 0.358% | 28.34% 14.7/critical
CVE-2026-46994 3.1: 9.8 0.354% | 28.03% 14.3/critical
CVE-2026-61237 3.1: 9.9 0.343% | 26.84% 14.3/critical
CVE-2026-47056 3.1: 10.0 0.331% | 25.51% 14.2/critical
CVE-2026-46982 3.1: 9.8 0.331% | 25.51% 13.9/critical
CVE-2026-60366 3.1: 10.0 0.310% | 23.34% 13.9/critical
CVE-2026-61239 3.1: 9.9 0.257% | 17.31% 12.5/critical
CVE-2026-60192 3.1: 8.1 0.348% | 27.39% 11.8/critical
CVE-2026-60193 3.1: 8.5 0.235% | 14.56% 10.1/critical
CVE-2026-60315 3.1: 8.2 0.244% | 15.67% 10.0/critical

NOTA: Le vulnerabilità sono ordinate per priorità operativa, calcolata combinando la gravità teorica (CVSS) con la probabilità reale di sfruttamento (EPSS). Se il dato EPSS non è ancora disponibile, la priorità è calcolata sul solo score CVSS.

tipi di attacco

CWE descrizione
CWE-284 Improper Access Control
CWE-306 Missing Authentication for Critical Function
CWE-94 Improper Control of Generation of Code ('Code Injection')
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

prodotti impattati

vendor prodotto & versioni
Oracle access manager
  • 14.1.2.1.0
  • 12.2.1.4.0
agile plm
  • 9.3.6
agile product lifecycle management for process
  • 6.2.4
autovue for agile product lifecycle management
  • 21.0.2
banking platform
  • da: 2.4.0 a: 2.9.0
bi publisher
  • 26.01.0.0.0
  • 12.2.1.4.0
  • 8.2.0.0.0
coherence
  • 12.2.1.4.0
  • 14.1.1.0.0
  • 15.1.1.0.0
  • 14.1.2.0.0
communications contacts server
  • 8.0.0.4.0
communications evolved communications application server
  • 7.1
communications instant messaging server
  • 10.0.1.4.0
communications network charging and control
  • da: 12.0.0 a: 12.0.3
  • 6.0.1
data integrator
  • 14.1.2.0.0
  • 12.2.1.4.0
enterprise manager base platform
  • 24.1.0.0.0
  • 13.5.0.0
  • 13.4.0.0
  • 13.3.0.0
global lifecycle management opatch
  • prima di: 12.2.0.1.20
http server
  • 14.1.2.0.0
  • 12.2.1.4.0
jd edwards enterpriseone orchestrator
  • prima di: 9.2.4.2
jd edwards enterpriseone tools
  • prima di: 9.2.4.2
mysql cluster
  • da: 8.4.0 a: 8.4.10
  • da: 8.0.0 a: 8.0.47
  • 9.7.1
  • 9.7.0
mysql connector\/net
  • da: 9.7.0 a: 9.7.1
mysql server
  • da: 8.4.0 a: 8.4.10
  • 9.7.1
  • 9.7.0
peoplesoft enterprise fin common objects argentina
  • 9.1
peoplesoft enterprise fin common objects brazil
  • 9.1
platform security for java
  • 12.2.1.4.0
  • 14.1.2.0.0
primavera unifier
  • da: 17.7 a: 17.12
  • 19.12
  • 18.8
  • 16.2
  • 16.1
retail integration bus
  • 14.1.3.2
  • 16.0.3
retail xstore point of service
  • 19.0
  • 18.0
  • 17.0
  • 16.0
  • 15.0
service delivery platform
  • 12.2.1.4.0
  • 14.1.2.0.0
unified directory
  • 14.1.2.1.0
  • 12.2.1.4.0
webcenter content
  • 14.1.2.0.0
  • 12.2.1.4.0
weblogic server
  • 12.2.1.4.0
  • 12.2.1.3.0
weblogic server proxy plug-in
  • 15.1.1.0.0