I recently read about two vulnerabilities in Confluence: CVE-2015-8398 and CVE-2015-8399 that were apparently fixed in version 5.8.17.
Were these vulnerabilities in the SaaS version of the product, or only the on-site/company hosted version of the product?