Where can I get more information about vulnerabilities described in the CPU Advisories and Security Alerts?
The level of information provided in the Critical Patch Update Advisory is designed to give customers sufficient outstanding of the vulnerabilities being fixed to make patching decisions, without giving attackers enough information to easily mount an attack. Oracle provides no more detailed information about security vulnerabilities than is provided in the Critical Patch Update documentation. My Oracle Support notes explaining the information in the risk matrices, as linked from the advisory “References” section, help to get the most from the information provided.