← Vulnerability feed

Vulnerability record · CVE-2021-2456 · published 21 July 2021

CVE-2021-2456: Oracle Business Intelligence Enterprise Edition unauthenticated takeover

Oracle · Business Intelligence

Oracle Business Intelligence Enterprise Edition 12.2.1.4.0 contains a flaw in the Analytics Web General component that is reachable over HTTP without authentication. Oracle rates it 9.8 critical with full confidentiality, integrity and availability impact, and states successful exploitation can result in takeover of the product. The record gives no root-cause detail beyond 'insufficient information' for the CWE.

9.8 CVSS 3.1 Critical EPSS 81% · top 0.4%
9.8CVSS 3.1 base score, v2 7.5
81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or user interaction and full takeover impact, plus a very high EPSS score, makes this an urgent patch target despite no KEV listing.

What it is

Oracle Business Intelligence Enterprise Edition 12.2.1.4.0 contains a flaw in the Analytics Web General component that is reachable over HTTP without authentication. Oracle rates it 9.8 critical with full confidentiality, integrity and availability impact, and states successful exploitation can result in takeover of the product. The record gives no root-cause detail beyond 'insufficient information' for the CWE.

Impact

An unauthenticated network attacker can fully compromise the BI Enterprise Edition instance, gaining control over its data and functions with high confidentiality, integrity and availability impact. Oracle describes the outcome as takeover of the product.

Attack surface

Reached over the network via HTTP against the Analytics Web General component; the CVSS vector shows no privileges and no user interaction required. Any internet- or network-exposed BI Enterprise Edition 12.2.1.4.0 deployment is in scope.

Exploitation

Not listed in CISA KEV and no ransomware use documented, but EPSS is very high at 0.814 (99.6th percentile), indicating strong predicted exploitation activity. References are vendor and third-party advisories only, with no public exploit tag in the record.

What to do

  • Apply the July 2021 Oracle Critical Patch Update for Business Intelligence Enterprise Edition 12.2.1.4.0 (cpujul2021).
  • If patching cannot be done immediately, remove direct network/HTTP exposure of the Analytics Web component and restrict access to trusted networks or a VPN.
  • Place the BI instance behind a reverse proxy or WAF with rules for the Analytics Web endpoints and monitor for anomalous requests.
  • Verify the deployed version and confirm whether 12.2.1.4.0 is present before assuming exposure.
  • Review logs and configuration for signs of prior compromise before and after patching.

Detection

  • Hunt web/proxy logs for unauthenticated POST/GET requests to Analytics Web General endpoints returning 200 or unusual response sizes.
  • Monitor for unexpected new administrative accounts, configuration changes or outbound connections from the BI server.
  • Alert on exploitation attempts against the Analytics Web path using vendor or ZDI advisory signatures.
  • Baseline normal BI traffic and alert on spikes in unauthenticated requests to the affected component.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-2456 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-17530Apache Struts forced OGNL evaluation enables remote code executionApache Struts 2.0.0 through 2.5.25 performs forced OGNL evaluation on raw user input placed in tag attributes, allowing expression language injection…KEVEPSS 96%analysed7.5CVE-2020-14864Oracle Business Intelligence Enterprise Edition path traversal allows unauthenticated data accessOracle Business Intelligence Enterprise Edition contains a path traversal flaw in its Installation component affecting versions 5.5.0.0.0, 12.2.1.3.0…KEVEPSS 97%analysed6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed9.8CVE-2022-23305Log4j 1.x JDBCAppender SQL injection via logged inputThe JDBCAppender in Log4j 1.2.x builds SQL statements from configuration parameters and PatternLayout converters, so logged values such as the %m mes…EPSS 67%analysed9.8CVE-2020-9480Apache spark missing authentication for critical function vulnerabilityIn Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shar…EPSS 29%9.8CVE-2020-2950Oracle Business Intelligence Enterprise Edition unauthenticated takeoverOracle Business Intelligence Enterprise Edition (Analytics Web General) contains an easily exploitable flaw affecting versions 5.5.0.0.0, 11.1.1.9.0,…EPSS 71%analysed9.8CVE-2018-8013Apache batik deserialization of untrusted data vulnerabilityIn Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name w…EPSS 19%8.8CVE-2026-71055Oracle business intelligence improper access control vulnerabilityVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported versio…EPSS 0.43%

Source: NIST National Vulnerability Database (record CVE-2021-2456), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.