Lucene search

K
atlassianDblackCONFSERVER-43333
HistoryJul 31, 2016 - 11:34 p.m.

Upgrade bundled Java to 8u101+

2016-07-3123:34:11
dblack
jira.atlassian.com
12

6.2 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

8.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

45.7%

Oracle’s Critical patch update for July includes some “unspecified vulnerability”, for example CVE-2016-3552 & CVE-2016-3503, fixes in the “install” component of java that may affect Confluence.

Affected configurations

Vulners
Node
atlassianconfluence_data_centerRange5.8.18
OR
atlassianconfluence_data_centerRange5.9.12
OR
atlassianconfluence_data_centerRange5.10.3
OR
atlassianconfluence_data_centerRange<5.10.4
OR
atlassianconfluence_data_centerRange<5.9.14
OR
atlassianconfluence_data_centerRange<5.10.9

6.2 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

8.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

45.7%