If you’re running Oracle WebLogic Server in production, you already know how seriously Oracle takes the patching lifecycle. Patch Set Updates (PSUs) roll out on a quarterly cadence, and falling behind even one or two cycles can leave your environment exposed to known CVEs — the kind that show up in audit reports and make everyone nervous.
This post walks through how I applied Patch 39164348 — the WLS PSU for version 15.1.1.0.260403 — using OPatch. I’ll cover what I did before touching anything, the actual apply process, and how to confirm everything landed cleanly.
Why I Don’t Skip PSUs
I’ve seen teams treat WebLogic patching as optional housekeeping. It isn’t. Each PSU from Oracle bundles a collection of security fixes, third-party library updates, and stability improvements that have been vetted against the platform. Skipping them means:
- Carrying known, unpatched CVEs in production
- Running outdated cryptographic libraries (in this case, BouncyCastle components)
- Losing Oracle’s ability to support you if something breaks — they’ll ask if you’re current first
- Failing compliance checks if you’re in a regulated industry
This particular patch touched Node Manager stability, Web Services modules, HTTP Client, and several security-related shared libraries. Worth the hour it takes.
What I Was Working With
Before starting, here’s a snapshot of the environment:
- Oracle Home:
/u01/Middleware/Oracle_Home - OPatch Version:
13.9.4.2.19 - Existing interim patches: None
Always verify your OPatch version before applying anything. If OPatch is outdated, you’ll get errors mid-apply and have to back out. Run this from your OPatch directory:
bash
./opatch version
You should see something like:
OPatch Version: 13.9.4.2.19
Then check what’s already installed:
bash
./opatch lspatches
In my case:
There are no Interim patches installed in this Oracle Home
Clean slate. Good to proceed.
Step 1: Get the Patch Package Extracted
The patch file from Oracle’s support portal came as:
p39164348_151100_Generic.zip
Unzip it:
bash
unzip p39164348_151100_Generic.zip
This creates a 39164348/ directory. Inside you’ll find the patch metadata and updated modules for things like:
- Node Manager
- WebLogic core app server components
- Security libraries
- Apache Commons (commons-lang3)
- BouncyCastle cryptography packages
- HTTP Client
- WLST components
Don’t move files around in there — OPatch reads the structure as-is.
Step 2: Stop Everything First
Before running OPatch apply, stop all WebLogic services. This means:
- Admin Server
- All Managed Servers
- Node Manager
If OPatch detects running processes associated with the Oracle Home, it will warn you and ask for confirmation. It’s cleaner — and safer — to bring everything down intentionally before you start.
Step 3: Apply the Patch
Navigate into the extracted patch directory:
bash
cd 39164348
Then kick off the apply:
bash
/u01/Middleware/Oracle_Home/OPatch/opatch apply
OPatch will work through a sequence of checks before it actually patches anything:
- Validates the Oracle Home path
- Reads the central inventory
- Backs up existing files that will be replaced
- Confirms you want to proceed with the apply
- Verifies patch prerequisites
This is where it will stop and ask you to confirm shutdown if it detects any running processes. Respond accordingly, and let it run.
Step 4: What Actually Got Updated
Once the apply completes, these are the components that were patched:
| Component | Description |
|---|---|
oracle.wls.common.nodemanager | Node Manager stability fixes |
oracle.wls.core.app.server | Core server runtime |
oracle.wls.libraries | WebLogic shared libraries |
oracle.webservices.wls | Web Services module |
oracle.http_client | HTTP Client update |
oracle.wls.security.core.sharedlib | Security core shared library |
oracle.org.bouncycastle.* | Cryptography library updates |
oracle.org.apache.commons.commons.lang3 | Apache Commons update |
Step 5: Confirm the Patch Landed
Once OPatch finishes, you’ll see:
Patch 39164348 successfully applied.
Then validate it’s registered in the inventory:
bash
/u01/Middleware/Oracle_Home/OPatch/opatch lspatches
Output:
39164348;WLS PATCH SET UPDATE 15.1.1.0.260403
That’s your confirmation. The patch is in, it’s registered, and OPatch knows about it for future conflict checks.
After the Patch: Don’t Skip These
Applying the patch is only part of the job. Before calling it done:
- Restart WebLogic services — Admin Server first, then Managed Servers, then Node Manager
- Test Admin Console access and verify managed servers come up cleanly
- Deploy a test application or exercise a critical business flow if your change control process requires it
- Check server logs — look for any anomalies at startup, especially around security providers and Node Manager connectivity
- Document the patch in your change log and CMDB if you have one
If Something Goes Wrong
OPatch version mismatch
The error will usually tell you what minimum version is required. Download the updated OPatch from Oracle MOS and install it into the Oracle Home before retrying.
Running processes detected
OPatch will warn you. Stop all WebLogic processes and re-run.
Inventory issues
If OPatch can’t locate your inventory, check that oraInst.loc points to the right location. You can specify it explicitly with the -invPtrLoc flag.
Need to roll back
If something goes sideways after the patch, you can roll back with:
bash
opatch rollback -id 39164348
OPatch will restore the files it backed up during the apply. Then bring your services back up and verify.
Recommended Screenshot Checkpoints
If you’re documenting this for your team or change management:
opatch versionoutput — confirms you’re running a supported OPatch version- Patch extraction output — shows the zip expanded correctly
opatch applyin progress — captures the validation and backup steps- Successful completion message — the line you want in your change record
- Final
opatch lspatches— your proof that the patch is registered
Closing Thought
Patching WebLogic isn’t glamorous work, but it’s the kind of thing that keeps production running without surprises. Patch 39164348 is a straightforward PSU — no complex conflicts, no unusual prerequisites — and applying it on a clean 15.1.1 installation is a low-risk, high-value maintenance task.
Get into a rhythm with Oracle’s quarterly PSU cadence and it becomes routine. Fall too far behind and it becomes a project.
Keep it routine.




