cbcvebase.
CVE-2021-2198
published 2021-04-22

CVE-2021-2198: Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). Supported versions that are affected are…

PriorityP267high8.2CVSS 3.1
AVNACLPRNUIRSCCHILAN
EPSS
79.94%
99.6th percentile
Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Knowledge Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Knowledge Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Knowledge Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

Affected

4 ranges
VendorProductVersion rangeFixed in
oracleknowledge_management12.1.1 – 12.1.3
oracleknowledge_management12.2.3 – 12.2.10
oracle_corporationknowledge_management
oracle_corporationknowledge_management

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is exploitable over HTTP without authentication, targeting Oracle Knowledge Management (Setup, Admin component) in Oracle E-Business Suite. Monitor for unauthenticated HTTP requests to Oracle Knowledge Management Setup/Admin endpoints.
  • The attack requires human interaction (e.g., a victim clicking a crafted link), suggesting a reflected/stored XSS or CSRF vector. Inspect HTTP traffic for suspicious cross-origin requests or injected payloads targeting Oracle Knowledge Management Setup/Admin pages.
  • The vulnerability has a Changed scope (S:C in CVSS vector), meaning a successful exploit can impact components beyond Oracle Knowledge Management itself. Monitor for lateral data access or privilege escalation across Oracle E-Business Suite components following suspicious Knowledge Management activity.
  • ·Affected versions span two major release lines: 12.1.1–12.1.3 and 12.2.3–12.2.10. Ensure patch applicability is validated against the exact installed version before deploying Oracle's April 2021 CPU fix.
  • ·The attack vector is Network with no authentication required and low attack complexity, meaning no special network positioning or credentials are needed by the attacker. Perimeter controls alone are insufficient if the application is internet-facing.

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_oracle8.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.