← Vulnerability feed

Vulnerability record · CVE-2021-2198 · published 22 April 2021

CVE-2021-2198: Oracle Knowledge Management unauthenticated data access via HTTP

Oracle · Knowledge Management

Oracle Knowledge Management (Setup, Admin component) in Oracle E-Business Suite 12.1.1-12.1.3 and 12.2.3-12.2.10 contains an easily exploitable flaw reachable over HTTP by an unauthenticated attacker. The record does not specify the underlying weakness (CWE is listed as insufficient information), but the CVSS vector indicates high confidentiality impact and low integrity impact with scope change. Because the component is exposed over the network and requires no credentials, it is a meaningful target for data theft and tampering.

8.2 CVSS 3.1 High EPSS 80% · top 0.4%
8.2CVSS 3.1 base score, v2 5.8
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Knowledge Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Knowledge Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Knowledge Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 8.2 with network reachability and no authentication, combined with a very high EPSS score, makes this a high-priority patch despite the required user interaction and lack of KEV listing.

What it is

Oracle Knowledge Management (Setup, Admin component) in Oracle E-Business Suite 12.1.1-12.1.3 and 12.2.3-12.2.10 contains an easily exploitable flaw reachable over HTTP by an unauthenticated attacker. The record does not specify the underlying weakness (CWE is listed as insufficient information), but the CVSS vector indicates high confidentiality impact and low integrity impact with scope change. Because the component is exposed over the network and requires no credentials, it is a meaningful target for data theft and tampering.

Impact

An attacker can gain unauthorized access to critical data or complete access to all Oracle Knowledge Management accessible data, plus unauthorized update, insert or delete access to some of that data. The scope change in the vector means other products may also be significantly impacted.

Attack surface

Reached over the network via HTTP against Oracle Knowledge Management; no authentication is required (PR:N), but successful exploitation requires human interaction from a person other than the attacker (UI:R).

Exploitation

Not listed in CISA KEV and no public exploit references are provided, but EPSS is very high at 0.799 (99.6th percentile), indicating strong predicted likelihood of exploitation activity.

What to do

  • Apply the Oracle April 2021 Critical Patch Update referenced in the vendor advisory, which covers Knowledge Management 12.1.1-12.1.3 and 12.2.3-12.2.10.
  • Restrict network access to Oracle E-Business Suite HTTP endpoints to trusted users and networks; do not expose Knowledge Management directly to the internet.
  • Enforce user awareness and phishing-resistant controls, since exploitation requires a victim to interact with attacker-supplied content.
  • Monitor and limit privileges on Knowledge Management data so that a compromise cannot cascade to other products via the scope change.
  • Verify patched versions after upgrade and re-scan exposed EBS instances for the affected component.

Detection

  • Review HTTP access logs for anomalous requests to Knowledge Management Setup/Admin endpoints, especially from unauthenticated or unexpected source IPs.
  • Alert on unusual read, insert, update or delete activity against Knowledge Management tables and records outside normal business patterns.
  • Correlate web requests with user interaction events to identify cases where a user was directed to attacker-controlled content before suspicious Knowledge Management access.
  • Monitor for outbound or lateral connections from EBS hosts to unfamiliar destinations that could indicate post-exploitation movement.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-2198 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2020-2841Oracle knowledge management vulnerabilityVulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). Supported versions that are affected a…EPSS 1.3%8.2CVE-2019-2660Oracle knowledge management vulnerabilityVulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: Setup, Admin). Supported versions that are affec…EPSS 1.3%8.2CVE-2017-10410Oracle knowledge management vulnerabilityVulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: Search). Supported versions that are affected ar…EPSS 1.6%8.2CVE-2017-10411Oracle knowledge management vulnerabilityVulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are aff…EPSS 1.6%8.2CVE-2017-10412Oracle knowledge management vulnerabilityVulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are aff…EPSS 1.6%8.2CVE-2017-3362Oracle knowledge management vulnerabilityVulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are aff…EPSS 1.6%8.2CVE-2017-3363Oracle knowledge management vulnerabilityVulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are aff…EPSS 1.2%8.2CVE-2017-3364Oracle knowledge management vulnerabilityVulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are aff…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2021-2198), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.