EXPOSURES › CVE-2019-3396
CVE-2019-3396
CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 95/100
ransomwarerceexploited-in-wild
Atlassian Confluence Server and Data Center had a server-side template injection vulnerability actively exploited by ransomware actors, enabling remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.70
Significant negative impact due to active exploitation and inclusion in KEV lists.
Strongly negative due to KEV listing indicating active exploitation.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is one of the highest-signal inputs for risk-based patch mana"
Negative, highlights active exploitation and potential for severe consequences.
"Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution, install persistent web shells, and steal cryptographic keys from exposed systems."
Neutral reporting of the vulnerability.
"Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution."
Neutral, lists the vulnerability in a database.
Neutral, simply lists the vulnerability in a database.
Neutral, describes the vulnerability in a list of CVEs.
Neutral, simply lists the vulnerability in a breach directory.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.