Improper privilege management in Jira Service Management Data Center - CVE-2025-22157
Published: May 21, 2025
Vulnerability identifier: #VU109587
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-22157
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to improper privilege management. A remote user can bypass implemented security restrictions and escalate privileges within the application.
Affected software
Jira Service Management Data Center
Jira Software Data Center
Jira Software Data Center
How to mitigate CVE-2025-22157
Install updates from vendor's website.
Jira Service Management Data Center - addressed in versions 5.12.20, 10.3.5, 10.5.1, 10.6.0
Jira Software Data Center - addressed in versions 9.12.20, 10.3.5, 10.5.1, 10.6.0
Jira Software Data Center - addressed in versions 9.12.20, 10.3.5, 10.5.1, 10.6.0