cbcvebase.
CVE-2021-2355
published 2021-07-21

CVE-2021-2355: Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are…

PriorityP262critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.41%
69.6th percentile
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Marketing accessible data as well as unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Affected

4 ranges
VendorProductVersion rangeFixed in
oraclemarketing12.1.1 – 12.1.3
oraclemarketing12.2.3 – 12.2.10
oracle_corporationmarketing
oracle_corporationmarketing

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is remotely exploitable over HTTP with no authentication required (PR:N/UI:N), targeting Oracle E-Business Suite Marketing Administration component — monitor for unauthenticated HTTP requests to Oracle Marketing Administration endpoints.
  • Affected versions are Oracle E-Business Suite 12.1.1–12.1.3 and 12.2.3–12.2.10; prioritize detection and patching on hosts running these specific version ranges.
  • Successful exploitation results in unauthorized creation, deletion, or modification of critical data AND unauthorized read access — alert on anomalous unauthenticated write/read activity against Oracle Marketing data stores.
  • ·The attack vector is Network with no privileges or user interaction required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), meaning any internet-exposed Oracle EBS instance running the affected versions is at critical risk without additional network-layer controls.
  • ·The vulnerability specifically affects the Marketing Administration component of Oracle Marketing within Oracle E-Business Suite; scope is limited to that component but impact on confidentiality and integrity is rated High.
  • ·Patch guidance is provided under Oracle's July 2021 Critical Patch Update (cpujul2021); ensure the advisory is consulted for the specific patch to apply.

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_oracle9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.