CVE-2021-2345 is a medium-severity vulnerability affecting Oracle Commerce Guided Search and Oracle Commerce Experience Manager (version 11.3.1.5), specifically within the Tools and Frameworks component. This easily exploitable flaw allows a low-privileged attacker with network access via HTTP to gain unauthorized read and limited modification access to accessible data. Successful exploitation requires human interaction from a victim and can impact additional products beyond the immediate Oracle Commerce components. The vulnerability has a CVSS 3.1 Base Score of 5.4, indicating a medium severity due to its low attack complexity and the requirement for user interaction, yet it can lead to partial confidentiality and integrity compromise. While the attack vector is network-based, the scope is changed, meaning impacts can extend beyond the vulnerable component. Currently, there is no evidence of active exploitation, nor are there any publicly available exploit codes in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage, suggesting a low level of public awareness or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.3.1.5CPE matchmatch criteria | cpe:2.3:a:oracle:commerce_experience_manager:11.3.1.5:*:*:*:*:*:*:* | ||
11.3.1.5CPE matchmatch criteria | cpe:2.3:a:oracle:commerce_guided_search:11.3.1.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.