Description
Due to a broken access control vulnerability in Confluence, an unauthenticated attacker can create an administrator account and get full access to the system
Remediation
Upgrade to the latest version of Confluence
References
Related Vulnerabilities
Oracle Database Server Improper Input Validation Vulnerability (CVE-2018-1000873)
PHP Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2011-0754)
Oracle Application Server Other Vulnerability (CVE-2002-0564)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-5205)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-3376)