Vulnerability record · CVE-2021-2400 · published 21 July 2021
CVE-2021-2400: Oracle BI Publisher unauthenticated data exposure via HTTP
Oracle · Bi Publisher
Oracle BI Publisher, part of Oracle Fusion Middleware, contains a vulnerability in the E-Business Suite - XDO component affecting versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated attacker with network access over HTTP can exploit it to read critical data. The record does not specify the underlying coding flaw, so the exact root cause is unknown.
Description
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 7.5 with network-reachable, unauthenticated, high-confidentiality impact and a very high EPSS score, though no confirmed in-the-wild exploitation or KEV listing.
What it is
Oracle BI Publisher, part of Oracle Fusion Middleware, contains a vulnerability in the E-Business Suite - XDO component affecting versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated attacker with network access over HTTP can exploit it to read critical data. The record does not specify the underlying coding flaw, so the exact root cause is unknown.
Impact
An attacker gains unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data, with confidentiality fully compromised but no integrity or availability impact.
Attack surface
Reachable over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or intranet-exposed BI Publisher endpoint is in scope.
Exploitation
Not listed in CISA KEV and no ransomware use documented, but EPSS is very high at 0.833 (99.7th percentile), indicating elevated likelihood of attempted exploitation. References are vendor and third-party advisories only, with no public exploit tag.
What to do
- Apply the Oracle July 2021 Critical Patch Update for BI Publisher versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0.
- Restrict network access to BI Publisher HTTP endpoints to trusted hosts and place them behind an authenticated reverse proxy or VPN.
- Monitor and log unauthenticated requests to BI Publisher/XDO endpoints and alert on anomalous access patterns.
- If patching cannot be done immediately, consider temporarily disabling or isolating the affected component.
- Review Oracle's advisory and ZDI-21-886 for any additional workaround guidance.
Detection
- Hunt web server and WAF logs for unauthenticated HTTP requests to BI Publisher/XDO paths, especially from unfamiliar source IPs.
- Baseline normal BI Publisher access and alert on spikes in unauthenticated requests or large data retrievals.
- Correlate outbound data volume from BI Publisher hosts with request logs to spot bulk data exfiltration.
- Monitor for scanning activity targeting Oracle Fusion Middleware/BI Publisher endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2021.html | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-886/ | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2021.html | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-886/ | Third Party Advisory |
Track CVE-2021-2400 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-2400), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.