← Vulnerability feed

Vulnerability record · CVE-2021-2400 · published 21 July 2021

CVE-2021-2400: Oracle BI Publisher unauthenticated data exposure via HTTP

Oracle · Bi Publisher

Oracle BI Publisher, part of Oracle Fusion Middleware, contains a vulnerability in the E-Business Suite - XDO component affecting versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated attacker with network access over HTTP can exploit it to read critical data. The record does not specify the underlying coding flaw, so the exact root cause is unknown.

7.5 CVSS 3.1 High EPSS 83% · top 0.3%
7.5CVSS 3.1 base score, v2 5.0
83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 7.5 with network-reachable, unauthenticated, high-confidentiality impact and a very high EPSS score, though no confirmed in-the-wild exploitation or KEV listing.

What it is

Oracle BI Publisher, part of Oracle Fusion Middleware, contains a vulnerability in the E-Business Suite - XDO component affecting versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated attacker with network access over HTTP can exploit it to read critical data. The record does not specify the underlying coding flaw, so the exact root cause is unknown.

Impact

An attacker gains unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data, with confidentiality fully compromised but no integrity or availability impact.

Attack surface

Reachable over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or intranet-exposed BI Publisher endpoint is in scope.

Exploitation

Not listed in CISA KEV and no ransomware use documented, but EPSS is very high at 0.833 (99.7th percentile), indicating elevated likelihood of attempted exploitation. References are vendor and third-party advisories only, with no public exploit tag.

What to do

  • Apply the Oracle July 2021 Critical Patch Update for BI Publisher versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0.
  • Restrict network access to BI Publisher HTTP endpoints to trusted hosts and place them behind an authenticated reverse proxy or VPN.
  • Monitor and log unauthenticated requests to BI Publisher/XDO endpoints and alert on anomalous access patterns.
  • If patching cannot be done immediately, consider temporarily disabling or isolating the affected component.
  • Review Oracle's advisory and ZDI-21-886 for any additional workaround guidance.

Detection

  • Hunt web server and WAF logs for unauthenticated HTTP requests to BI Publisher/XDO paths, especially from unfamiliar source IPs.
  • Baseline normal BI Publisher access and alert on spikes in unauthenticated requests or large data retrievals.
  • Correlate outbound data volume from BI Publisher hosts with request logs to spot bulk data exfiltration.
  • Monitor for scanning activity targeting Oracle Fusion Middleware/BI Publisher endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-2400 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-71059Oracle bi publisher improper access control vulnerabilityVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0…EPSS 0.43%9.9CVE-2026-60719Oracle bi publisher improper input validation vulnerabilityVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0…EPSS 0.39%9.8CVE-2026-60173Oracle bi publisher improper access control vulnerabilityVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.…EPSS 0.51%9.8CVE-2024-21082Oracle bi publisher xml external entity (xxe) vulnerabilityVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.0.0.0.0 an…EPSS 0.81%9.8CVE-2021-21346XStream deserialization allows remote code executionXStream before 1.4.16 deserializes untrusted XML without adequate type restrictions, letting a remote attacker load and execute arbitrary code by man…EPSS 76%analysed9.8CVE-2017-5645Apache Log4j 2 socket server deserialization allows remote code executionApache Log4j 2.x before 2.8.2 deserializes binary log events received over its TCP or UDP socket server without validating the payload. A crafted ser…EPSS 90%analysed8.8CVE-2026-71058Oracle bi publisher improper access control vulnerabilityVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0…EPSS 0.43%8.8CVE-2024-21254Oracle bi publisher missing authorization vulnerabilityVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.0.0.0.0, 7.6…EPSS 0.52%

Source: NIST National Vulnerability Database (record CVE-2021-2400), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.