cbcvebase.
CVE-2016-5897
published 2017-02-01

CVE-2016-5897: IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in…

PriorityP424medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.64%
46.5th percentile
IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

Affected

10 ranges
VendorProductVersion rangeFixed in
ibmjazz_reporting_service
ibmjazz_reporting_service
ibmjazz_reporting_service
ibm_corporationjazz_reporting_service
ibm_corporationjazz_reporting_service
ibm_corporationjazz_reporting_service
ibm_corporationjazz_reporting_service
ibm_corporationjazz_reporting_service
ibm_corporationjazz_reporting_service
ibm_corporationjazz_reporting_service

CVSS provenance

nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.