Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Oct 13, 2023

CVE-2023-22515

High
EPSS 94.3%CISA KEVRansomware
Atlassian/Confluence Data Center and Server

Description

Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.

EPSS — Exploit Probability

94.3%

Higher than 100.0% of all CVEs

Required Action

https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html; https://nvd.nist.gov/vuln/detail/CVE-2023-22515

Risk Assessment

CRITICAL
In CISA KEV
High EPSS
Ransomware

Details

Severity
High
EPSS
94.3%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Oct 5, 2023

Added to KEV

Oct 5, 2023

Remediation Due

Oct 13, 2023

Affected Product

Atlassian

Confluence Data Center and Server

View all Atlassian CVEs