« Volver al listado

CVE-2016-4317

Estado: ModificadaMedia (5.4)—

Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-4317",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Atlassian Confluence Server before 5.9.11",
          "versions": [
            {
              "status": "affected",
              "version": "Atlassian Confluence Server before 5.9.11"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-04-10T03:59:01.153",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/97513",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://confluence.atlassian.com/doc/confluence-5-9-11-release-notes-827123763.html",
      "source": "cret@cert.org"
    },
    {
      "url": "https://jira.atlassian.com/browse/CONF-42713",
      "source": "cret@cert.org"
    },
    {
      "url": "https://jira.atlassian.com/browse/CONFSERVER-42713",
      "tags": [
        "Issue Tracking"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/97513",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://confluence.atlassian.com/doc/confluence-5-9-11-release-notes-827123763.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://jira.atlassian.com/browse/CONF-42713",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://jira.atlassian.com/browse/CONFSERVER-42713",
      "tags": [
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page."
    },
    {
      "lang": "es",
      "value": "Atlassian Confluence Server en versiones anteriores a 5.9.11 tiene XSS en la página viewmyprofile.action."
    }
  ],
  "lastModified": "2026-06-17T00:47:20.353",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:atlassian:confluence:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F09BAEE9-BBC2-4ACB-9622-45E67A41151B",
              "versionEndIncluding": "5.9.10"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}