2 Critical Security Updates

This chapter describes the Critical Security Fixes done in Oracle GoldenGate. Oracle updates the release notes periodically after the software release. This document is accurate at the time of publication.

Critical Security Updates 19c (19.31.0.0.260529): June 2026

Oracle recommends upgrading to this patch as it has critical security bug fixes.

Critical Security Updates 19c (19.31.0.0.260506): May 2026

Oracle recommends upgrading to this patch as it has critical security bug fixes for Microservices Architecture.

Critical Security Updates 19c (19.1.0.0.210720): July 2021

This release includes critical security fixes for various CVEs. Oracle strongly recommends that you upgrade to this release of Oracle GoldenGate.

jquery-1.6.1.min.js was removed to address the following CVEs:

CVE-2011-4969

CVE-2012-6708

CVE-2015-9251

CVE-2019-11358

CVE-2020-11022

CVE-2020-11023

Critical Security Updates 19c (19.1.0.0.201013): October 2020

Upgrade to JQUERY 3.5.1 to address CVE-2020-11022

Upgrading to JQUERY 3.5.1 addresses CVE-2020-11022.

Critical Security Updates 19c (19.1.0): July 2020

Critical Security Fix

Release 19c (19.1.0.0.4): Oracle strongly recommends upgrading to the latest OPatch utility to resolve CVE-2020-9546. Oracle GoldenGate components themselves are not impacted by CVE-2020-9546, only the OPatch utility, which is why the OPatch upgrade is recommended.

Critical Security Updates 19c (19.1.0)

Critical Security Fixes

Release 19c (19.1.0.0.4): This release includes critical security fixes including the following CVEs. Oracle strongly recommends that you upgrade to this release of Oracle GoldenGate.

CVE-2019-11358: JQUERY upgrade to 3.4.0

CVE-2018-11058: The update for CVE-2018-11058 also addresses the following:

  • CVE-2016-0701

  • CVE-2016-2183

  • CVE-2016-6306

  • CVE-2016-8610

  • CVE-2018-11054

  • CVE-2018-11055

  • CVE-2018-11056

  • CVE-2018-11057

  • CVE-2018-15769

For more information, please refer to https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html.