cbcvebase.

Ibm Jazz Reporting Service vulnerabilities

55 known vulnerabilities affecting ibm/jazz_reporting_service.

Total CVEs
55
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH7MEDIUM43LOW4

Vulnerabilities

Page 1 of 3
CVE-2015-7465P2HIGHCVSS 8.8ExploitedRansomwarev6.02016-01-10
CVE-2015-7465 [HIGH] CWE-352 CVE-2015-7465: Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reportin Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
nvd
CVE-2019-4651P3CRITICALCVSS 9.8v6.0.6.12020-01-09
CVE-2019-4651 [CRITICAL] CWE-89 CVE-2019-4651: IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could sen IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170962.
nvd
CVE-2016-0315P3HIGHCVSS 8.8v5.0v5.0.1+3 more2016-07-08
CVE-2016-0315 [HIGH] CWE-284 CVE-2016-0315: The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x befor The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 maintain session ID validity after a logout action, which allows remote authenticated users to hijack sessions by leveraging an unattended workstation.
nvd
CVE-2016-0319P3HIGHCVSS 7.5v6.0v6.0.12016-11-25
CVE-2016-0319 [HIGH] CWE-284 CVE-2016-0319: The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6. The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administrators to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issu
nvd
CVE-2024-25051P3HIGHCVSS 7.2v7.0.2v7.0.32025-04-02
CVE-2024-25051 [HIGH] CWE-613 CVE-2024-25051: IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allo IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system.
nvd
CVE-2016-2889P3HIGHCVSS 8.8v5.0v5.0.1+4 more2016-07-08
CVE-2016-2889 [HIGH] CWE-352 CVE-2016-2889: Cross-site request forgery (CSRF) vulnerability in the Report Builder and Data Collection Component Cross-site request forgery (CSRF) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016, 6.0 and 6.0.1 before 6.0.1 ifix005, and 6.0.2 before ifix002 allows remote authenticated users to hijack the authentication of arbitrary users.
nvd
CVE-2015-7464P4HIGHCVSS 7.5v5.0v5.0.1+2 more2016-01-29
CVE-2015-7464 [HIGH] CVE-2015-7464: Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 bef Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote attackers to cause a denial of service (Report Builder server outage) via a crafted request to a Report Builder instance URL.
nvd
CVE-2015-7470P4HIGHCVSS 7.5v5.0v5.0.1+2 more2016-01-17
CVE-2015-7470 [HIGH] CWE-200 CVE-2015-7470: Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 bef Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors, as demonstrated by login information.
nvd
CVE-2018-1639P4MEDIUMCVSS 6.5≥ 5.0, ≤ 5.0.2≥ 6.0, ≤ 6.0.2+11 more2018-11-16
CVE-2018-1639 [MEDIUM] CWE-200 CVE-2018-1639: The Report Builder of Jazz Reporting Service 5.0 through 5.0.2 and 6.0 through 6.0.6 could allow an The Report Builder of Jazz Reporting Service 5.0 through 5.0.2 and 6.0 through 6.0.6 could allow an authenticated user to obtain sensitive information beyond its assigned privileges. IBM X-Force ID: 144579.
nvd
CVE-2016-0314P4MEDIUMCVSS 6.5v5.0v5.0.1+3 more2016-07-08
CVE-2016-0314 [MEDIUM] CVE-2016-0314: The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x befor The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allow remote authenticated users to conduct clickjacking attacks via unspecified vectors.
nvd
CVE-2021-20535P4MEDIUMCVSS 5.4v6.0.6.1v7.0+2 more2021-05-13
CVE-2021-20535 [MEDIUM] CWE-918 CVE-2021-20535: IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forge IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 198834.
nvd
CVE-2016-0317P4MEDIUMCVSS 6.5v6.0v6.0.12016-11-25
CVE-2016-0317 [MEDIUM] CWE-284 CVE-2016-0317: Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
nvd
CVE-2020-4533P4MEDIUMCVSS 6.1v6.0.6v6.0.6.1+1 more2020-08-10
CVE-2020-4533 [MEDIUM] CWE-79 CVE-2020-4533: IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulne IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182717.
nvd
CVE-2020-4539P4MEDIUMCVSS 6.1v6.0.2v6.0.6+3 more2020-08-10
CVE-2020-4539 [MEDIUM] CWE-79 CVE-2020-4539: IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripti IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2020-4541P4MEDIUMCVSS 6.1v7.0v7.0.12020-08-10
CVE-2020-4541 [MEDIUM] CWE-79 CVE-2020-4541: IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability a IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183039.
nvd
CVE-2016-5897P4MEDIUMCVSS 5.4v6.0v6.0.1+1 more2017-02-01
CVE-2016-5897 [MEDIUM] CWE-79 CVE-2016-5897: IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject mal IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
nvd
CVE-2020-4718P4MEDIUMCVSS 5.4v6.0.6v6.0.6.1+2 more2020-11-19
CVE-2020-4718 [MEDIUM] CWE-79 CVE-2020-4718: IBM Jazz Reporting Service 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to stored cross-site scripti IBM Jazz Reporting Service 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 187731.
nvd
CVE-2018-1918P4MEDIUMCVSS 5.4≥ 6.0.3, ≤ 6.0.6v6.0.3+3 more2019-01-08
CVE-2018-1918 [MEDIUM] CWE-79 CVE-2018-1918: IBM Jazz Reporting Service (JRS) 6.0.3, 6.0.4, 6.0.5, and 6.0.6 is vulnerable to cross-site scriptin IBM Jazz Reporting Service (JRS) 6.0.3, 6.0.4, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152785.
nvd
CVE-2017-1750P4MEDIUMCVSS 5.4v5.0v5.0.1+7 more2018-04-25
CVE-2017-1750 [MEDIUM] CWE-79 CVE-2017-1750: IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 135523.
nvd
CVE-2018-1363P4MEDIUMCVSS 5.4v5.0v5.0.1+7 more2018-04-25
CVE-2018-1363 [MEDIUM] CWE-79 CVE-2018-1363: IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137448.
nvd
Ibm Jazz Reporting Service vulnerabilities | cvebase