Akira Ransomware – Active IOCs
May 23, 2025Multiple Cisco Unified Vulnerabilities
May 23, 2025Akira Ransomware – Active IOCs
May 23, 2025Multiple Cisco Unified Vulnerabilities
May 23, 2025Severity
High
Analysis Summary
CVE-2025-22157 CVSS:7.2
Atlassian Jira Core Data Center and Server and Jira Service Management Data Center and Server could allow a remote authenticated attacker to gain elevated privileges on the system.
CVE-2023-22514 CVSS:7.8
Atlassian Sourcetree for Mac and Sourcetree for Windows could allow a local attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction.
CVE-2024-21703 CVSS:6.4
Atlassian Confluence Data Center could allow a remote authenticated attacker to gain elevated privileges on the system, caused by improper access control in confluence.cfg.xml configuration file. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.
CVE-2024-21697 CVSS:8.8
Atlassian Sourcetree for Windows and Mac could allow a remote attacker to execute arbitrary code on the system, caused by an unspecified flaw. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Impact
- Code Execution
- Privilege Escalation
Indicators of Compromise
CVE
CVE-2025-22157
CVE-2023-22514
CVE-2024-21703
CVE-2024-21697
Affected Vendors
Affected Products
- Atlassian Jira Core Data Center 10.5.0
- Atlassian Jira Core Server 9.12.0
- Atlassian Jira Core Data Center 10.4.0
- Atlassian Jira Core Data Center 10.4.1
- Atlassian Jira Core Data Center 10.3.0
- Atlassian Jira Core Data Center 10.3.4
- Atlassian Jira Core Data Center 9.12.0
- Atlassian Jira Core Data Center 9.12.19
- Atlassian Jira Core Server 9.12.19
- Atlassian Jira Service Management Data Center 10.5.0
- Atlassian Jira Service Management Data Center 10.4.0
- Atlassian Jira Service Management Data Center 10.4.1
- Atlassian Jira Service Management Data Center 10.3.0
- Atlassian Jira Service Management Data Center 10.3.4
- Atlassian Jira Service Management Data Center 5.12.0
- Atlassian Jira Service Management Data Center 5.12.19
- Atlassian Jira Service Management Server 5.12.0
- Atlassian Jira Service Management Server 5.12.19
- Atlassian Sourcetree for Mac - 3.4.14
- Atlassian Sourcetree for Windows - 3.4.14
- Atlassian Confluence Data Center - 8.7.1
- Atlassian Sourcetree for Mac - 4.2.8
- Atlassian Sourcetree for Windows - 3.4.19
Remediation
Refer to Atlassian Security Advisory for patch, upgrade or suggested workaround information.