Apps Unlimited Value of Support Series: Critical Patch Updates and Security Alerts
Critical Patch Update (CPU) is the primary mechanism for providing security bug fixes for Oracle products and are available quarterly to all customers with valid Support contracts. Security Alerts are provided for vulnerability fixes deemed too critical to wait for the next Critical Patch Update. It is highly recommended that CPUs and Security Alerts patches be applied as soon as possible after they become available. You can find further information, along with the links to download security patches, on the “Critical Patch Updates, Security Alerts and Bulletins” page: https://bit.ly/ORCL-SecurityAlerts
Due to the sensitivity of these bugs and fixes, details are not included within the patch information and reports of security vulnerabilities to the Oracle Support team are handled via an SR with utmost security. If you are not a Support customer or partner, you can send a report of a potential security issue to secalert_us@oracle.com.