The Setup Wizard in Atlassian JIRA Enterprise Edition before 3.12.1 does not properly restrict setup attempts after setup is complete, which allows remote attackers to change the default language.
http://www.securityfocus.com/bid/27095
http://secunia.com/advisories/27954
http://confluence.atlassian.com/display/JIRA/JIRA+Security+Advisory+2007-12-24