← Vulnerability feed

Vulnerability record · CVE-2021-2401 · published 21 July 2021

CVE-2021-2401: Oracle BI Publisher XXE allows unauthenticated data read

Oracle · Bi Publisher

Oracle BI Publisher contains an XML external entity (XXE) flaw in the E-Business Suite - XDO component. An unauthenticated attacker with network access can send crafted XML over HTTP and read a subset of data accessible to the application. The issue affects versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0.

5.3 CVSS 3.1 Medium EPSS 85% · top 0.3% CWE-611 · XML external entity (XXE)
5.3CVSS 3.1 base score, v2 5.0
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityCVSS 5.3 with confidentiality-only impact, but unauthenticated network reachability and a very high EPSS score raise the practical risk.

What it is

Oracle BI Publisher contains an XML external entity (XXE) flaw in the E-Business Suite - XDO component. An unauthenticated attacker with network access can send crafted XML over HTTP and read a subset of data accessible to the application. The issue affects versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0.

Impact

An attacker gains unauthorized read access to a limited subset of Oracle BI Publisher data. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network via HTTP with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). Any exposed BI Publisher endpoint that parses XML is a candidate entry point.

Exploitation

Not listed in CISA KEV and no public exploit tags appear in the references, but EPSS is very high at 0.8482 (99.7th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Apply the Oracle July 2021 Critical Patch Update for BI Publisher versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0.
  • Disable external entity and DTD processing in the XML parser used by the XDO component.
  • Restrict network access to BI Publisher HTTP endpoints to trusted networks or a reverse proxy.
  • Monitor and rate-limit XML upload or report-generation requests from untrusted sources.

Detection

  • Inspect HTTP request bodies to BI Publisher endpoints for DOCTYPE declarations, ENTITY definitions or SYSTEM/PUBLIC identifiers.
  • Alert on outbound DNS or HTTP connections originating from the BI Publisher server to unexpected external hosts.
  • Review application and web server logs for anomalous XML parsing errors or repeated report requests from single sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-2401 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-71059Oracle bi publisher improper access control vulnerabilityVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0…EPSS 0.43%9.9CVE-2026-60719Oracle bi publisher improper input validation vulnerabilityVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0…EPSS 0.39%9.8CVE-2026-60173Oracle bi publisher improper access control vulnerabilityVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.…EPSS 0.51%9.8CVE-2024-21082Oracle bi publisher xml external entity (xxe) vulnerabilityVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.0.0.0.0 an…EPSS 0.81%9.8CVE-2021-21346XStream deserialization allows remote code executionXStream before 1.4.16 deserializes untrusted XML without adequate type restrictions, letting a remote attacker load and execute arbitrary code by man…EPSS 76%analysed9.8CVE-2017-5645Apache Log4j 2 socket server deserialization allows remote code executionApache Log4j 2.x before 2.8.2 deserializes binary log events received over its TCP or UDP socket server without validating the payload. A crafted ser…EPSS 90%analysed8.8CVE-2026-71058Oracle bi publisher improper access control vulnerabilityVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0…EPSS 0.43%8.8CVE-2024-21254Oracle bi publisher missing authorization vulnerabilityVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.0.0.0.0, 7.6…EPSS 0.52%

Source: NIST National Vulnerability Database (record CVE-2021-2401), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.