Vulnerability record · CVE-2021-2456 · published 21 July 2021
CVE-2021-2456: Oracle Business Intelligence Enterprise Edition unauthenticated takeover
Oracle · Business Intelligence
Oracle Business Intelligence Enterprise Edition 12.2.1.4.0 contains a flaw in the Analytics Web General component that is reachable over HTTP without authentication. Oracle rates it 9.8 critical with full confidentiality, integrity and availability impact, and states successful exploitation can result in takeover of the product. The record gives no root-cause detail beyond 'insufficient information' for the CWE.
Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction and full takeover impact, plus a very high EPSS score, makes this an urgent patch target despite no KEV listing.
What it is
Oracle Business Intelligence Enterprise Edition 12.2.1.4.0 contains a flaw in the Analytics Web General component that is reachable over HTTP without authentication. Oracle rates it 9.8 critical with full confidentiality, integrity and availability impact, and states successful exploitation can result in takeover of the product. The record gives no root-cause detail beyond 'insufficient information' for the CWE.
Impact
An unauthenticated network attacker can fully compromise the BI Enterprise Edition instance, gaining control over its data and functions with high confidentiality, integrity and availability impact. Oracle describes the outcome as takeover of the product.
Attack surface
Reached over the network via HTTP against the Analytics Web General component; the CVSS vector shows no privileges and no user interaction required. Any internet- or network-exposed BI Enterprise Edition 12.2.1.4.0 deployment is in scope.
Exploitation
Not listed in CISA KEV and no ransomware use documented, but EPSS is very high at 0.814 (99.6th percentile), indicating strong predicted exploitation activity. References are vendor and third-party advisories only, with no public exploit tag in the record.
What to do
- Apply the July 2021 Oracle Critical Patch Update for Business Intelligence Enterprise Edition 12.2.1.4.0 (cpujul2021).
- If patching cannot be done immediately, remove direct network/HTTP exposure of the Analytics Web component and restrict access to trusted networks or a VPN.
- Place the BI instance behind a reverse proxy or WAF with rules for the Analytics Web endpoints and monitor for anomalous requests.
- Verify the deployed version and confirm whether 12.2.1.4.0 is present before assuming exposure.
- Review logs and configuration for signs of prior compromise before and after patching.
Detection
- Hunt web/proxy logs for unauthenticated POST/GET requests to Analytics Web General endpoints returning 200 or unusual response sizes.
- Monitor for unexpected new administrative accounts, configuration changes or outbound connections from the BI server.
- Alert on exploitation attempts against the Analytics Web path using vendor or ZDI advisory signatures.
- Baseline normal BI traffic and alert on spikes in unauthenticated requests to the affected component.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2021.html | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-885/ | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2021.html | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-885/ | Third Party Advisory |
Track CVE-2021-2456 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-2456), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.