Lucene search

K
atlassian[email protected]JRASERVER-72211
HistoryMar 11, 2021 - 7:39 p.m.

Tomcat PersistenceManager vulnerabilities - CVE-2021-25329 and CVE-2021-25122

2021-03-1119:39:59
jira.atlassian.com
35
tomcat
persistencemanager
vulnerabilities
atlassian jira
server

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

60.0%

Affected versions of Atlassian Jira Server and Data Center are susceptible to Tomcat PersistenceManager vulnerabilities.

Affected versions:

  • ≤ 8.16.0

Fixed versions:

  • pending

Affected configurations

Vulners
Node
atlassianjira_data_centerRange8.15.0
OR
atlassianjira_data_centerRange8.13.4
OR
atlassianjira_data_centerRange8.5.12
OR
atlassianjira_data_centerRange<8.17.0
OR
atlassianjira_data_centerRange<8.5.16
OR
atlassianjira_data_centerRange<8.13.8
VendorProductVersionCPE
atlassianjira_data_center*cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

60.0%