cbcvebase.

Ibm Jazz Reporting Service vulnerabilities

55 known vulnerabilities affecting ibm/jazz_reporting_service.

Total CVEs
55
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH7MEDIUM43LOW4

Vulnerabilities

Page 2 of 3
CVE-2019-4184P4MEDIUMCVSS 5.4≥ 6.0, ≤ 6.0.6.1v6.0+7 more2019-05-29
CVE-2019-4184 [MEDIUM] CWE-79 CVE-2019-4184: IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerabi IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158974.
nvd
CVE-2018-2004P4MEDIUMCVSS 5.4≥ 6.0, ≤ 6.0.6v6.0+6 more2019-04-29
CVE-2018-2004 [MEDIUM] CWE-79 CVE-2018-2004: IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulne IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155006.
nvd
CVE-2016-2888P4MEDIUMCVSS 5.4v5.0v5.0.1+3 more2016-07-08
CVE-2016-2888 [MEDIUM] CVE-2016-2888: Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) i Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0313 and CVE-2016-0350.
nvd
CVE-2017-1096P4MEDIUMCVSS 5.4v5.0v5.0.1+5 more2017-07-05
CVE-2017-1096 [MEDIUM] CWE-79 CVE-2017-1096: IBM Jazz Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerabili IBM Jazz Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120656.
nvd
CVE-2017-1490P4MEDIUMCVSS 5.3v6.0v6.0.1+3 more2017-09-14
CVE-2017-1490 [MEDIUM] CWE-200 CVE-2017-1490: An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0 An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information.
nvd
CVE-2019-4497P4MEDIUMCVSS 5.4v6.0v6.0.1+7 more2019-10-01
CVE-2019-4497 [MEDIUM] CWE-79 CVE-2019-4497: IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulne IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164118.
nvd
CVE-2019-4495P4MEDIUMCVSS 5.4v6.0v6.0.1+6 more2019-10-01
CVE-2019-4495 [MEDIUM] CWE-79 CVE-2019-4495: IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulne IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164116.
nvd
CVE-2019-4494P4MEDIUMCVSS 5.4v6.0v6.0.1+6 more2019-10-01
CVE-2019-4494 [MEDIUM] CWE-79 CVE-2019-4494: IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulne IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164115.
nvd
CVE-2016-0350P4MEDIUMCVSS 5.4v5.0v5.0.1+3 more2016-07-08
CVE-2016-0350 [MEDIUM] CVE-2016-0350: Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) i Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0313.
nvd
CVE-2016-0313P4MEDIUMCVSS 5.4v5.0v5.0.1+3 more2016-07-08
CVE-2016-0313 [MEDIUM] CWE-79 CVE-2016-0313: Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) i Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0350.
nvd
CVE-2020-4419P4MEDIUMCVSS 5.4v6.0.6v6.0.6.1+1 more2020-05-28
CVE-2020-4419 [MEDIUM] CWE-79 CVE-2020-4419: IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulne IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180071.
nvd
CVE-2016-6039P4MEDIUMCVSS 5.4v6.0v6.0.1+1 more2017-02-01
CVE-2016-6039 [MEDIUM] CWE-79 CVE-2016-6039: IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows us IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-6054P4MEDIUMCVSS 5.4v5.0v5.0.1+4 more2017-02-01
CVE-2016-6054 [MEDIUM] CWE-79 CVE-2016-6054: IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-5899P4MEDIUMCVSS 5.4v5.0v5.0.1+4 more2017-02-01
CVE-2016-5899 [MEDIUM] CWE-79 CVE-2016-5899: IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows us IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-6047P4MEDIUMCVSS 5.4v6.0.22017-02-01
CVE-2016-6047 [MEDIUM] CWE-79 CVE-2016-6047: IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows us IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2020-4933P4MEDIUMCVSS 5.4v6.0.6.1v7.0+2 more2021-02-18
CVE-2020-4933 [MEDIUM] CWE-79 CVE-2020-4933: IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. Thi IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191751.
nvd
CVE-2017-1340P4MEDIUMCVSS 5.0v6.0.42017-11-01
CVE-2017-1340 [MEDIUM] CWE-200 CVE-2017-1340: IBM Jazz Reporting Service (JRS) 6.0.4 could allow an authenticated user to obtain information on an IBM Jazz Reporting Service (JRS) 6.0.4 could allow an authenticated user to obtain information on another server that the current report builder interacts with. IBM X-Force ID: 126455.
nvd
CVE-2016-0318P4MEDIUMCVSS 5.0v6.0v6.0.12016-11-25
CVE-2016-0318 [MEDIUM] CWE-284 CVE-2016-0318: Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does n Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, which allows remote attackers to obtain access by leveraging an unattended workstation.
nvd
CVE-2016-9987P4MEDIUMCVSS 5.4v5.0v5.0.1+5 more2017-07-05
CVE-2016-9987 [MEDIUM] CWE-79 CVE-2016-9987: IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120553.
nvd
CVE-2016-9986P4MEDIUMCVSS 5.4v5.0v5.0.1+5 more2017-07-05
CVE-2016-9986 [MEDIUM] CWE-79 CVE-2016-9986: IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120552.
nvd