1) why would you not use a vpn or other gateway between confluence server and the internet?
2) presumably for the same reason they ran confluence as root: no idea what they're doing (forgivable) or lazy (unforgivable)
2) presumably for the same reason they ran confluence as root: no idea what they're doing (forgivable) or lazy (unforgivable)
It doesn't really help you to use a security product in front of your vulnerable product when the security product turns out to be roughly equally vulnerable.