Changes in This Release for Oracle Database Security Assessment Tool

The Oracle Database Security Assessment Tool 4.2 (March 2026) release has been updated to detect CVEs from the latest Critical Patch Update for Oracle Database versions 19c, 21c, and 26ai.

The Oracle Database Security Assessment Tool supports Oracle AI Database 26ai and Oracle Autonomous AI Databases.

  • Updated sections/checks:

    INFO.PATCH: Enhanced with CVE detection for comprehensive vulnerability assessment.

  • General:
    • Secure Authentication: Oracle recommends that you use a secure method to run the Oracle Database Security Assessment Tool (DBSAT), and avoid entering the authentication password on the command line. DBSAT now issues a warning message to encourage secure authentication.

      The command-line password based authentication method is now deprecated and will be desupported in a future release.

    • Oracle JRE Requirement: Oracle Java Runtime Environment (Oracle JRE) 17 (Oracle JDK 17) is now the minimum prerequisite.

    • Best Practices Terminology: "Oracle Best Practices (OBP)" findings are now labeled "Oracle Recommended Practices (ORP)".

Downloading and Installing Oracle Database Security Assessment Tool

Known Issues

Microsoft Excel Font Size Display

Some versions of Microsoft Excel may display text on the screen with a font too large to fit in spreadsheet cells, even though it prints at the correct size output. If this happens, resize the columns slightly to make the text visible.