JPCERT-AT-2023-0003 JPCERT/CC 2023-01-18 <<< JPCERT/CC Alert 2023-01-18 >>> Oracle Releases Critical Patch Update, January 2023 https://www.jpcert.or.jp/english/at/2023/at230003.html I. Overview On January 17, 2023 (Local Time), Oracle released critical patch updates for multiple Oracle products. Oracle Corporation Oracle Critical Patch Update Advisory - January 2023 https://www.oracle.com/security-alerts/cpujan2023.html Users of the affected products are recommended to update to the latest version appropriately by referring to the information provided by Oracle. Oracle Corporation Text Form of Oracle Critical Patch Update - January 2023 Risk Matrices https://www.oracle.com/security-alerts/cpujan2023verbose.html II. Solutions Oracle has provided patches that address vulnerabilities in each product. Some products or applications may not run properly after updating the software to the latest version. Please update to the latest version after considering any possible impacts to the products or applications. In addition, there are cases where Java JRE is pre-installed on the PC or WebLogic is used in software products for servers. Please check if any of the affected products is included in the PCs or servers that you use. The latest version of Java can be downloaded from the following link. Java Downloads for All Operating Systems https://www.java.com/en/download/manual.jsp III. References Oracle Corporation Oracle Java SE Support Roadmap https://www.oracle.com/java/technologies/java-se-support-roadmap.html Oracle Corporation Critical Patch Updates, Security Alerts and Bulletins https://www.oracle.com/security-alerts/ Oracle Corporation January 2023 Critical Patch Update Released https://blogs.oracle.com/security/post/january-2023-cpu-released If you have any information regarding this alert, please contact JPCERT/CC. ====================================================================== JPCERT Coordination Center (Early Warning Group) MAIL: ew-info@jpcert.or.jp https://www.jpcert.or.jp/english/