Vendor: Deview Studios
Product: Issue AI Analytics for Jira Data Center
Fixed Versions: 9.1.6, 10.1.6, and 11.1.6
Discoverer: NATO Communications and Information Agency (NCIA)
Deview Studios has released security updates for Issue AI Analytics for Jira Data Center to address two local information disclosure vulnerabilities.
These issues affect Issue AI Analytics for Jira Data Center versions before 9.1.6, before 10.1.6, and before 11.1.6.
Vendor assessment indicates that exploitation generally requires privileged database or host access. No direct remote unauthenticated attack path has been identified.
The following versions of Issue AI Analytics for Jira Data Center are affected:
The vulnerabilities have been addressed in:
A vulnerability in Issue AI Analytics for Jira Data Center could allow a local attacker to obtain sensitive information through the product’s legacy proxy-password encryption functionality.
This issue is classified as:
Exploitation generally requires privileged database or host access.
A vulnerability in Issue AI Analytics for Jira Data Center could allow a local attacker to obtain sensitive information due to the use of a cryptographically weak pseudo-random number generator.
This issue is classified as:
Exploitation generally requires privileged database or host access.
Deview Studios recommends that all customers running affected versions of Issue AI Analytics for Jira Data Center upgrade to one of the fixed versions:
We extend various collaboration platforms by developing native integrations and applications. Our mission is to create best-in-class productivity tools for small and large businesses.