Vulnerability record · CVE-2021-2198 · published 22 April 2021
CVE-2021-2198: Oracle Knowledge Management unauthenticated data access via HTTP
Oracle · Knowledge Management
Oracle Knowledge Management (Setup, Admin component) in Oracle E-Business Suite 12.1.1-12.1.3 and 12.2.3-12.2.10 contains an easily exploitable flaw reachable over HTTP by an unauthenticated attacker. The record does not specify the underlying weakness (CWE is listed as insufficient information), but the CVSS vector indicates high confidentiality impact and low integrity impact with scope change. Because the component is exposed over the network and requires no credentials, it is a meaningful target for data theft and tampering.
Description
Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Knowledge Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Knowledge Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Knowledge Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Automated analysis
high priorityCVSS 8.2 with network reachability and no authentication, combined with a very high EPSS score, makes this a high-priority patch despite the required user interaction and lack of KEV listing.
What it is
Oracle Knowledge Management (Setup, Admin component) in Oracle E-Business Suite 12.1.1-12.1.3 and 12.2.3-12.2.10 contains an easily exploitable flaw reachable over HTTP by an unauthenticated attacker. The record does not specify the underlying weakness (CWE is listed as insufficient information), but the CVSS vector indicates high confidentiality impact and low integrity impact with scope change. Because the component is exposed over the network and requires no credentials, it is a meaningful target for data theft and tampering.
Impact
An attacker can gain unauthorized access to critical data or complete access to all Oracle Knowledge Management accessible data, plus unauthorized update, insert or delete access to some of that data. The scope change in the vector means other products may also be significantly impacted.
Attack surface
Reached over the network via HTTP against Oracle Knowledge Management; no authentication is required (PR:N), but successful exploitation requires human interaction from a person other than the attacker (UI:R).
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is very high at 0.799 (99.6th percentile), indicating strong predicted likelihood of exploitation activity.
What to do
- Apply the Oracle April 2021 Critical Patch Update referenced in the vendor advisory, which covers Knowledge Management 12.1.1-12.1.3 and 12.2.3-12.2.10.
- Restrict network access to Oracle E-Business Suite HTTP endpoints to trusted users and networks; do not expose Knowledge Management directly to the internet.
- Enforce user awareness and phishing-resistant controls, since exploitation requires a victim to interact with attacker-supplied content.
- Monitor and limit privileges on Knowledge Management data so that a compromise cannot cascade to other products via the scope change.
- Verify patched versions after upgrade and re-scan exposed EBS instances for the affected component.
Detection
- Review HTTP access logs for anomalous requests to Knowledge Management Setup/Admin endpoints, especially from unauthenticated or unexpected source IPs.
- Alert on unusual read, insert, update or delete activity against Knowledge Management tables and records outside normal business patterns.
- Correlate web requests with user interaction events to identify cases where a user was directed to attacker-controlled content before suspicious Knowledge Management access.
- Monitor for outbound or lateral connections from EBS hosts to unfamiliar destinations that could indicate post-exploitation movement.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.oracle.com/security-alerts/cpuapr2021.html | PatchVendor Advisory |
| https://www.oracle.com/security-alerts/cpuapr2021.html | PatchVendor Advisory |
Track CVE-2021-2198 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-2198), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.