MEDIUM · 4.0

CVE-2012-2927

The TM Software Tempo plugin before 6.4.3.1, 6.5.x before 6.5.0.2, and 7.x before 7.0.3 for Atlassian JIRA does not properly restrict the capabilities of third-party XML parsers, which allows remote a...

Vulnerability Description

The TM Software Tempo plugin before 6.4.3.1, 6.5.x before 6.5.0.2, and 7.x before 7.0.3 for Atlassian JIRA does not properly restrict the capabilities of third-party XML parsers, which allows remote authenticated users to cause a denial of service (resource consumption) via unspecified vectors.

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
Tm SoftwareTempo<= 6.4.3
Tm SoftwareTempo6.3.0jira42
Tm SoftwareTempo6.3.2jira42
AtlassianJira-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-2927?

CVE-2012-2927 is a vulnerability with a CVSS score of 4.0 (MEDIUM). The TM Software Tempo plugin before 6.4.3.1, 6.5.x before 6.5.0.2, and 7.x before 7.0.3 for Atlassian JIRA does not properly restrict the capabilities of third-party XML parsers, which allows remote a...

How severe is CVE-2012-2927?

CVE-2012-2927 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-2927?

Check the references section above for vendor advisories and patch information. Affected products include: Tm Software Tempo, Tm Software Tempo6.3.0, Tm Software Tempo6.3.2, Atlassian Jira.