S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Feb 1, 2024

CVE-2019-3398 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in Atlassian Confluence Server and Data Center affects v. before 6.15.2.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2019-3398
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Confluenceby Atlassian
AFFECTED< unspecifiedSAFE ✓≥ unspecified
Updated Aug 21, 2026View on NVD →
Detail

Atlassian Confluence Server and Data Center is a collaboration and content management tool that is widely used by companies and organizations around the world. It is used for creating, sharing, and managing content such as documents, spreadsheets, presentations, and more. The platform is popular due to its ease of use and customization options, which allow organizations to tailor the platform to suit their specific needs.

However, the platform has recently been hit by a major vulnerability, known as CVE-2019-3398. This vulnerability is related to a path traversal flaw in the downloadallattachments resource of the Confluence platform. The flaw allows a remote attacker, who has permission to add attachments to pages and/or blogs or create a new space or a personal space or has ‘Admin’ permissions for a space, to exploit the vulnerability and write files to arbitrary locations. This can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center.

The consequences of the exploit of this vulnerability are severe, and can result in a complete loss of control over the affected system. An attacker who successfully exploits the vulnerability can write files to arbitrary locations, which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. This can lead to the installation of malware or other unwanted software, as well as to the theft of sensitive data.

In conclusion, the CVE-2019-3398 vulnerability in Atlassian Confluence Server and Data Center is a serious security issue that can lead to significant data breaches and other malicious activities. By taking these precautions, organizations can protect themselves from this vulnerability and minimize the risk of a successful attack. Using the pro features of the s4e.io platform, companies and individuals can easily and quickly learn about vulnerabilities in their digital assets, so they can stay ahead of the game when it comes to cybersecurity.

 

REFERENCES

Solution Advice

Fortunately, there are precautions that can be taken to protect against this vulnerability. Here are some suggestions:

  • Apply the latest security patches and updates provided by the vendor.
  • Limit access to users who have permission to add attachments to pages and/or blogs, create a new space or a personal space or have ‘Admin’ permissions for a space.
  • Disable the downloadallattachments resource of the Confluence platform.
  • Monitor the network for suspicious activity, and take immediate action if any is detected.
  • Educate users on the risks of opening email attachments or clicking on links from untrusted sources.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-3398 scanner - Remote Code Execution (RCE) vulnerability in Atlassian Confluence Server and Data Center | S4E