CVE-2012-2927: TM Software Tempo

Medium severity, CVSS 4.0. EPSS: 1.2% chance of exploitation in the next 30 days.

The TM Software Tempo plugin before 6.4.3.1, 6.5.x before 6.5.0.2, and 7.x before 7.0.3 for Atlassian JIRA does not properly restrict the capabilities of third-party XML parsers, which allows remote authenticated users to cause a denial of service (resource consumption) via unspecified vectors.

Affected products

  • TM Software Tempo: up to and including 6.4.3; version 2.2 only; version 2.3 only; version 2.3.1 only; version 2.4.1 only; version 2.5.1 only; …
  • TM Software TEMPO6.3.0: version jira42 only
  • TM Software TEMPO6.3.2: version jira42 only

Published 2012-05-22. Last modified 2026-06-16.