Ibm Jazz Reporting Service vulnerabilities
55 known vulnerabilities affecting ibm/jazz_reporting_service.
Total CVEs
55
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH7MEDIUM43LOW4
Vulnerabilities
Page 2 of 3
CVE-2019-4184P4MEDIUMCVSS 5.4≥ 6.0, ≤ 6.0.6.1v6.0+7 more2019-05-29
CVE-2019-4184 [MEDIUM] CWE-79 CVE-2019-4184: IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerabi
IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158974.
nvd
CVE-2018-2004P4MEDIUMCVSS 5.4≥ 6.0, ≤ 6.0.6v6.0+6 more2019-04-29
CVE-2018-2004 [MEDIUM] CWE-79 CVE-2018-2004: IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulne
IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155006.
nvd
CVE-2016-2888P4MEDIUMCVSS 5.4v5.0v5.0.1+3 more2016-07-08
CVE-2016-2888 [MEDIUM] CVE-2016-2888: Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) i
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0313 and CVE-2016-0350.
nvd
CVE-2017-1096P4MEDIUMCVSS 5.4v5.0v5.0.1+5 more2017-07-05
CVE-2017-1096 [MEDIUM] CWE-79 CVE-2017-1096: IBM Jazz Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerabili
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120656.
nvd
CVE-2017-1490P4MEDIUMCVSS 5.3v6.0v6.0.1+3 more2017-09-14
CVE-2017-1490 [MEDIUM] CWE-200 CVE-2017-1490: An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0
An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information.
nvd
CVE-2019-4497P4MEDIUMCVSS 5.4v6.0v6.0.1+7 more2019-10-01
CVE-2019-4497 [MEDIUM] CWE-79 CVE-2019-4497: IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulne
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164118.
nvd
CVE-2019-4495P4MEDIUMCVSS 5.4v6.0v6.0.1+6 more2019-10-01
CVE-2019-4495 [MEDIUM] CWE-79 CVE-2019-4495: IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulne
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164116.
nvd
CVE-2019-4494P4MEDIUMCVSS 5.4v6.0v6.0.1+6 more2019-10-01
CVE-2019-4494 [MEDIUM] CWE-79 CVE-2019-4494: IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulne
IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164115.
nvd
CVE-2016-0350P4MEDIUMCVSS 5.4v5.0v5.0.1+3 more2016-07-08
CVE-2016-0350 [MEDIUM] CVE-2016-0350: Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) i
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0313.
nvd
CVE-2016-0313P4MEDIUMCVSS 5.4v5.0v5.0.1+3 more2016-07-08
CVE-2016-0313 [MEDIUM] CWE-79 CVE-2016-0313: Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) i
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0350.
nvd
CVE-2020-4419P4MEDIUMCVSS 5.4v6.0.6v6.0.6.1+1 more2020-05-28
CVE-2020-4419 [MEDIUM] CWE-79 CVE-2020-4419: IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulne
IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180071.
nvd
CVE-2016-6039P4MEDIUMCVSS 5.4v6.0v6.0.1+1 more2017-02-01
CVE-2016-6039 [MEDIUM] CWE-79 CVE-2016-6039: IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows us
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-6054P4MEDIUMCVSS 5.4v5.0v5.0.1+4 more2017-02-01
CVE-2016-6054 [MEDIUM] CWE-79 CVE-2016-6054: IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-5899P4MEDIUMCVSS 5.4v5.0v5.0.1+4 more2017-02-01
CVE-2016-5899 [MEDIUM] CWE-79 CVE-2016-5899: IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows us
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-6047P4MEDIUMCVSS 5.4v6.0.22017-02-01
CVE-2016-6047 [MEDIUM] CWE-79 CVE-2016-6047: IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows us
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2020-4933P4MEDIUMCVSS 5.4v6.0.6.1v7.0+2 more2021-02-18
CVE-2020-4933 [MEDIUM] CWE-79 CVE-2020-4933: IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. Thi
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191751.
nvd
CVE-2017-1340P4MEDIUMCVSS 5.0v6.0.42017-11-01
CVE-2017-1340 [MEDIUM] CWE-200 CVE-2017-1340: IBM Jazz Reporting Service (JRS) 6.0.4 could allow an authenticated user to obtain information on an
IBM Jazz Reporting Service (JRS) 6.0.4 could allow an authenticated user to obtain information on another server that the current report builder interacts with. IBM X-Force ID: 126455.
nvd
CVE-2016-0318P4MEDIUMCVSS 5.0v6.0v6.0.12016-11-25
CVE-2016-0318 [MEDIUM] CWE-284 CVE-2016-0318: Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does n
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, which allows remote attackers to obtain access by leveraging an unattended workstation.
nvd
CVE-2016-9987P4MEDIUMCVSS 5.4v5.0v5.0.1+5 more2017-07-05
CVE-2016-9987 [MEDIUM] CWE-79 CVE-2016-9987: IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120553.
nvd
CVE-2016-9986P4MEDIUMCVSS 5.4v5.0v5.0.1+5 more2017-07-05
CVE-2016-9986 [MEDIUM] CWE-79 CVE-2016-9986: IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120552.
nvd