Ibm Jazz Reporting Service vulnerabilities
55 known vulnerabilities affecting ibm/jazz_reporting_service.
Total CVEs
55
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH7MEDIUM43LOW4
Vulnerabilities
Page 1 of 3
CVE-2025-27550LOWCVSS 3.5v7.0.3v7.1+2 more2026-02-04
CVE-2025-27550 [LOW] CWE-497 CVE-2025-27550: IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive
IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server.
cvelistv5nvd
CVE-2025-1823LOWCVSS 3.5v7.0.3v7.1+2 more2026-02-04
CVE-2025-1823 [LOW] CWE-770 CVE-2025-1823: IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial o
IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resources.
cvelistv5nvd
CVE-2025-2134LOWCVSS 3.5v7.0.3v7.1+2 more2026-02-04
CVE-2025-2134 [LOW] CWE-410 CVE-2025-2134: IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's p
IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.
cvelistv5nvd
CVE-2024-25051HIGHCVSS 7.2v7.0.2v7.0.32025-04-02
CVE-2024-25051 [MEDIUM] CWE-613 CVE-2024-25051: IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allo
IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system.
cvelistv5nvd
CVE-2024-25052MEDIUMCVSS 4.4v7.0.32024-06-13
CVE-2024-25052 [MEDIUM] CWE-256 CVE-2024-25052: IBM Jazz Reporting Service 7.0.3 stores user credentials in plain clear text which can be read by an
IBM Jazz Reporting Service 7.0.3 stores user credentials in plain clear text which can be read by an admin user. IBM X-Force ID: 283363.
cvelistv5nvd
CVE-2021-20535MEDIUMCVSS 5.4v6.0.6.1v7.0+2 more2021-05-13
CVE-2021-20535 [MEDIUM] CWE-918 CVE-2021-20535: IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forge
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 198834.
cvelistv5nvd
CVE-2020-4933MEDIUMCVSS 5.4v6.0.6.1v7.0+2 more2021-02-18
CVE-2020-4933 [MEDIUM] CWE-79 CVE-2020-4933: IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. Thi
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191751.
cvelistv5nvd
CVE-2020-4718MEDIUMCVSS 5.4v6.0.6v6.0.6.1+2 more2020-11-19
CVE-2020-4718 [MEDIUM] CWE-79 CVE-2020-4718: IBM Jazz Reporting Service 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to stored cross-site scripti
IBM Jazz Reporting Service 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 187731.
cvelistv5nvd
CVE-2020-4533MEDIUMCVSS 6.1v6.0.6v6.0.6.1+1 more2020-08-10
CVE-2020-4533 [MEDIUM] CWE-79 CVE-2020-4533: IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulne
IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182717.
cvelistv5nvd
CVE-2020-4539MEDIUMCVSS 6.1v6.0.2v6.0.6+3 more2020-08-10
CVE-2020-4539 [MEDIUM] CWE-79 CVE-2020-4539: IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripti
IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2020-4541MEDIUMCVSS 6.1v7.0v7.0.12020-08-10
CVE-2020-4541 [MEDIUM] CWE-79 CVE-2020-4541: IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability a
IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183039.
cvelistv5nvd
CVE-2020-4419MEDIUMCVSS 5.4v6.0.6v6.0.6.1+1 more2020-05-28
CVE-2020-4419 [MEDIUM] CWE-79 CVE-2020-4419: IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulne
IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180071.
cvelistv5nvd
CVE-2019-4651CRITICALCVSS 9.8v6.0.6.12020-01-09
CVE-2019-4651 [CRITICAL] CWE-89 CVE-2019-4651: IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could sen
IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170962.
nvd
CVE-2019-4497MEDIUMCVSS 5.4v6.0v6.0.1+7 more2019-10-01
CVE-2019-4497 [MEDIUM] CWE-79 CVE-2019-4497: IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulne
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164118.
cvelistv5nvd
CVE-2019-4494MEDIUMCVSS 5.4v6.0v6.0.1+6 more2019-10-01
CVE-2019-4494 [MEDIUM] CWE-79 CVE-2019-4494: IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulne
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164115.
cvelistv5nvd
CVE-2019-4495MEDIUMCVSS 5.4v6.0v6.0.1+6 more2019-10-01
CVE-2019-4495 [MEDIUM] CWE-79 CVE-2019-4495: IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulne
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164116.
cvelistv5nvd
CVE-2019-4184MEDIUMCVSS 5.4≥ 6.0, ≤ 6.0.6.1v6.0+7 more2019-05-29
CVE-2019-4184 [MEDIUM] CWE-79 CVE-2019-4184: IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerabi
IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158974.
cvelistv5nvd
CVE-2019-4047MEDIUMCVSS 4.3v6.0.62019-04-29
CVE-2019-4047 [MEDIUM] CWE-269 CVE-2019-4047: IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log
IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest user, and obtain the information of the server execution. IBM X-Force ID: 156243.
cvelistv5nvd
CVE-2018-2004MEDIUMCVSS 5.4≥ 6.0, ≤ 6.0.6v6.0+6 more2019-04-29
CVE-2018-2004 [MEDIUM] CWE-79 CVE-2018-2004: IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulne
IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155006.
cvelistv5nvd
CVE-2018-1918MEDIUMCVSS 5.4≥ 6.0.3, ≤ 6.0.6v6.0.3+3 more2019-01-08
CVE-2018-1918 [MEDIUM] CWE-79 CVE-2018-1918: IBM Jazz Reporting Service (JRS) 6.0.3, 6.0.4, 6.0.5, and 6.0.6 is vulnerable to cross-site scriptin
IBM Jazz Reporting Service (JRS) 6.0.3, 6.0.4, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152785.
cvelistv5nvd
1 / 3Next →