Vulnerability record · CVE-2021-2401 · published 21 July 2021
CVE-2021-2401: Oracle BI Publisher XXE allows unauthenticated data read
Oracle · Bi Publisher
Oracle BI Publisher contains an XML external entity (XXE) flaw in the E-Business Suite - XDO component. An unauthenticated attacker with network access can send crafted XML over HTTP and read a subset of data accessible to the application. The issue affects versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0.
Description
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Automated analysis
medium priorityCVSS 5.3 with confidentiality-only impact, but unauthenticated network reachability and a very high EPSS score raise the practical risk.
What it is
Oracle BI Publisher contains an XML external entity (XXE) flaw in the E-Business Suite - XDO component. An unauthenticated attacker with network access can send crafted XML over HTTP and read a subset of data accessible to the application. The issue affects versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0.
Impact
An attacker gains unauthorized read access to a limited subset of Oracle BI Publisher data. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network via HTTP with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). Any exposed BI Publisher endpoint that parses XML is a candidate entry point.
Exploitation
Not listed in CISA KEV and no public exploit tags appear in the references, but EPSS is very high at 0.8482 (99.7th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Apply the Oracle July 2021 Critical Patch Update for BI Publisher versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0.
- Disable external entity and DTD processing in the XML parser used by the XDO component.
- Restrict network access to BI Publisher HTTP endpoints to trusted networks or a reverse proxy.
- Monitor and rate-limit XML upload or report-generation requests from untrusted sources.
Detection
- Inspect HTTP request bodies to BI Publisher endpoints for DOCTYPE declarations, ENTITY definitions or SYSTEM/PUBLIC identifiers.
- Alert on outbound DNS or HTTP connections originating from the BI Publisher server to unexpected external hosts.
- Review application and web server logs for anomalous XML parsing errors or repeated report requests from single sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2021.html | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-887/ | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2021.html | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-887/ | Third Party Advisory |
Track CVE-2021-2401 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-2401), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.