CVE-2025-22166
BaseFortify
Publication date: 2025-10-21
Last updated on: 2025-12-05
Assigner: Atlassian
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| atlassian | confluence_data_center | From 8.5.0 (inc) to 8.5.25 (exc) |
| atlassian | confluence_data_center | From 9.2.0 (inc) to 9.2.7 (exc) |
| atlassian | confluence_data_center | From 10.0.0 (inc) to 10.0.2 (exc) |
| atlassian | confluence_server | From 8.5.0 (inc) to 8.5.25 (exc) |
| atlassian | confluence_server | From 9.2.0 (inc) to 9.2.7 (exc) |
| atlassian | confluence_server | From 10.0.0 (inc) to 10.0.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-405 | The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric." |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a High severity Denial of Service (DoS) issue in Confluence Data Center starting from version 2.0. It allows an attacker to disrupt the availability of services on a host connected to a network, making resources temporarily or indefinitely unavailable to intended users.
How can this vulnerability impact me? :
The impact of this vulnerability is that an attacker can cause a Denial of Service, making the affected Confluence Data Center services unavailable to legitimate users. This disruption can affect business operations relying on these services.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, you should upgrade your Confluence Data Center instance to the latest version. If upgrading to the latest version is not possible, upgrade to one of the specified supported fixed versions: 8.5.25 or later for Confluence Data Center and Server 8.5, 9.2.7 or later for version 9.2, or 10.0.2 or later for version 10.0.