CVE-2021-2401
Oracle Analytics Publisher vulnerability analysis and mitigation

Overview

CVE-2021-2401 is a vulnerability in Oracle Business Intelligence DOMParser that allows remote attackers to disclose sensitive information on affected installations. The vulnerability affects Oracle Business Intelligence versions prior to 0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. The vulnerability was discovered in March 2021 and publicly disclosed in July 2021 (ZDI Advisory).

Technical details

The vulnerability exists within the DOMParser endpoint, which listens on TCP port 9502 by default. The specific flaw is due to improper restriction of XML External Entity (XXE) references. When a crafted document specifying a URI is processed, the XML parser accesses the URI and embeds the contents back into the XML document for further processing. The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) (ZDI Advisory).

Impact

An attacker can leverage this vulnerability to disclose sensitive information in the context of the service account. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle Business Intelligence (ZDI Advisory).

Mitigation and workarounds

Oracle has issued an update to correct this vulnerability as part of the July 2021 Critical Patch Update. Users should apply the security patches without delay to protect their systems (ZDI Advisory, Oracle Advisory).

Additional resources


SourceThis report was generated using AI

Related Oracle Analytics Publisher vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-21254HIGH8.8
  • Oracle Analytics PublisherOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoYesOct 15, 2024
CVE-2025-50060HIGH8.1
  • Oracle Analytics PublisherOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoYesJul 15, 2025
CVE-2025-30724HIGH7.5
  • Oracle Analytics PublisherOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoYesApr 15, 2025
CVE-2025-61754MEDIUM6.5
  • Oracle Analytics PublisherOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoNoOct 21, 2025
CVE-2025-30723MEDIUM5.4
  • Oracle Analytics PublisherOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoYesApr 15, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management