Vulnerabilities > CVE-2012-2927 - Resource Management Errors vulnerability in TM Software Tempo
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The TM Software Tempo plugin before 6.4.3.1, 6.5.x before 6.5.0.2, and 7.x before 7.0.3 for Atlassian JIRA does not properly restrict the capabilities of third-party XML parsers, which allows remote authenticated users to cause a denial of service (resource consumption) via unspecified vectors.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family | CGI abuses |
NASL id | JIRA_5_0_1.NASL |
description | According to its self-reported version number, the version of Atlassian JIRA hosted on the remote web server is prior to 5.0.1. It is, therefore, potentially affected by an XML parsing flaw due to improper restrictions on the capabilities of third-party parsers. A remote, authenticated attacker can exploit this to perform a denial of service attack against JIRA. The Tempo and Gliffy plugins for JIRA are also affected by this vulnerability; however, Nessus did not confirm that these plugins are installed. If you are using these plugins with any version of JIRA, you should upgrade or disable them. Note that Nessus has not tested for these issues but has instead relied only on the application |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 59329 |
published | 2012-06-01 |
reporter | This script is Copyright (C) 2012-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/59329 |
title | Atlassian JIRA < 5.0.1 XML Parsing DoS |
code |
|
References
- http://confluence.atlassian.com/display/JIRA/JIRA+Security+Advisory+2012-05-17
- http://confluence.atlassian.com/display/JIRA/JIRA+Security+Advisory+2012-05-17
- http://osvdb.org/81993
- http://osvdb.org/81993
- http://secunia.com/advisories/49166
- http://secunia.com/advisories/49166
- http://www.securityfocus.com/bid/53595
- http://www.securityfocus.com/bid/53595
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75697
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75697