CVE-2019-3397
Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed version for 6.0.x), and from 6.1.0 before 6.1.2 (the fixed version for 6.1.x) allow remote attackers who have admin permissions to achieve remote code execution on a Bitbucket server instance via path traversal through the Data Center migration tool.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 4.40%
- Percentil entre todas las CVEs puntuadas: 91
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-22
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-3397",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "security@atlassian.com",
"affectedData": [
{
"vendor": "Atlassian",
"product": "Bitbucket Data Center",
"versions": [
{
"status": "affected",
"version": "5.13.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.13.6",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.14.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.14.4",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.15.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.15.3",
"versionType": "custom"
},
{
"status": "affected",
"version": "6.0.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "6.0.3",
"versionType": "custom"
},
{
"status": "affected",
"version": "6.1.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "6.1.2",
"versionType": "custom"
}
]
}
]
}
],
"published": "2019-06-03T14:29:00.293",
"references": [
{
"url": "https://jira.atlassian.com/browse/BSERV-11706",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "security@atlassian.com"
},
{
"url": "https://jira.atlassian.com/browse/BSERV-11706",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed version for 6.0.x), and from 6.1.0 before 6.1.2 (the fixed version for 6.1.x) allow remote attackers who have admin permissions to achieve remote code execution on a Bitbucket server instance via path traversal through the Data Center migration tool."
},
{
"lang": "es",
"value": "Atlassian Bitbucket Data Center con licencias que comienzan con la versión 5.13.0 anterior a la 5.13.6 (la versión fija para 5.13.x), desde la versión 5.14.0 anterior a la 5.14.4 (versión fija para la 5.14.x), desde la versión 5.15.0 hasta la 5.15. 3 (versión fija para 5.15.x), de versión 5.16.0 anterior a 5.16.3 (versión fija de 5.16.x), desde versión 6.0.0 anterior a 6.0.3 (versión fija para 6.0.x), y desde versión 6.1.0 anterior a 6.1.2 (la versión fija para 6.1.x), permite a los atacanterior remotos con permisos de administrador lograr la ejecución de código remota en una instancia del servidor Bitbucket por medio de un salto de path (path trasversal) de la herramienta de migración del Centro de Datos."
}
],
"lastModified": "2026-06-17T02:35:05.753",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A6215D87-F4E1-445C-B201-89F411229CA4",
"versionEndExcluding": "5.13.6",
"versionStartIncluding": "5.13.0"
},
{
"criteria": "cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6EFC24FA-DFFB-45B6-8F63-3AFDE1CC5464",
"versionEndExcluding": "5.14.4",
"versionStartIncluding": "5.14.0"
},
{
"criteria": "cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6FD74B56-390D-48CB-93BB-0452869D58D7",
"versionEndExcluding": "5.15.3",
"versionStartIncluding": "5.15.0"
},
{
"criteria": "cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0F6EA7D6-40E5-4F3D-B5C4-16DB7AB421A6",
"versionEndExcluding": "5.16.3",
"versionStartIncluding": "5.16.0"
},
{
"criteria": "cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D61084D-DA80-4EAD-AABA-DD94F9A69475",
"versionEndExcluding": "6.0.3",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9E69F799-F16F-4C25-AE84-5D73CBEAD71D",
"versionEndExcluding": "6.1.2",
"versionStartIncluding": "6.1.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@atlassian.com"
}