Ibm Jazz Reporting Service vulnerabilities
55 known vulnerabilities affecting ibm/jazz_reporting_service.
Total CVEs
55
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH7MEDIUM43LOW4
Vulnerabilities
Page 3 of 3
CVE-2016-0318MEDIUMCVSS 5.0v6.0v6.0.12016-11-25
CVE-2016-0318 [MEDIUM] CWE-284 CVE-2016-0318: Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does n
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, which allows remote attackers to obtain access by leveraging an unattended workstation.
nvd
CVE-2016-0317MEDIUMCVSS 6.5v6.0v6.0.12016-11-25
CVE-2016-0317 [MEDIUM] CWE-284 CVE-2016-0317: Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
nvd
CVE-2016-2889HIGHCVSS 8.8v5.0v5.0.1+4 more2016-07-08
CVE-2016-2889 [HIGH] CWE-352 CVE-2016-2889: Cross-site request forgery (CSRF) vulnerability in the Report Builder and Data Collection Component
Cross-site request forgery (CSRF) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016, 6.0 and 6.0.1 before 6.0.1 ifix005, and 6.0.2 before ifix002 allows remote authenticated users to hijack the authentication of arbitrary users.
nvd
CVE-2016-0315HIGHCVSS 8.8v5.0v5.0.1+3 more2016-07-08
CVE-2016-0315 [HIGH] CWE-284 CVE-2016-0315: The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x befor
The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 maintain session ID validity after a logout action, which allows remote authenticated users to hijack sessions by leveraging an unattended workstation.
nvd
CVE-2016-2888MEDIUMCVSS 5.4v5.0v5.0.1+3 more2016-07-08
CVE-2016-2888 [MEDIUM] CVE-2016-2888: Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) i
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0313 and CVE-2016-0350.
nvd
CVE-2016-0350MEDIUMCVSS 5.4v5.0v5.0.1+3 more2016-07-08
CVE-2016-0350 [MEDIUM] CVE-2016-0350: Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) i
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0313.
nvd
CVE-2016-0314MEDIUMCVSS 6.5v5.0v5.0.1+3 more2016-07-08
CVE-2016-0314 [MEDIUM] CVE-2016-0314: The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x befor
The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allow remote authenticated users to conduct clickjacking attacks via unspecified vectors.
nvd
CVE-2016-0313MEDIUMCVSS 5.4v5.0v5.0.1+3 more2016-07-08
CVE-2016-0313 [MEDIUM] CWE-79 CVE-2016-0313: Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) i
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0350.
nvd
CVE-2015-7464HIGHCVSS 7.5v5.0v5.0.1+2 more2016-01-29
CVE-2015-7464 [HIGH] CVE-2015-7464: Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 bef
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote attackers to cause a denial of service (Report Builder server outage) via a crafted request to a Report Builder instance URL.
nvd
CVE-2015-7470HIGHCVSS 7.5v5.0v5.0.1+2 more2016-01-17
CVE-2015-7470 [HIGH] CWE-200 CVE-2015-7470: Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 bef
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors, as demonstrated by login information.
nvd
CVE-2015-7469MEDIUMCVSS 4.3v5.0v5.0.1+2 more2016-01-17
CVE-2015-7469 [MEDIUM] CWE-264 CVE-2015-7469: Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 bef
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended read-only restrictions by leveraging a JazzGuest role.
nvd
CVE-2015-7467MEDIUMCVSS 5.4v5.0v5.0.1+2 more2016-01-17
CVE-2015-7467 [MEDIUM] CWE-79 CVE-2015-7467: Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz Reporting Service (JRS) 5.x b
Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2015-7468MEDIUMCVSS 4.3v5.0v5.0.1+2 more2016-01-17
CVE-2015-7468 [MEDIUM] CWE-264 CVE-2015-7468: Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 bef
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended restrictions on administrator tasks via unspecified vectors.
nvd
CVE-2015-7465HIGHCVSS 8.8Exploitedv6.02016-01-10
CVE-2015-7465 [HIGH] CWE-352 CVE-2015-7465: Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reportin
Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
nvd
CVE-2015-7466LOWCVSS 3.1v6.02016-01-10
CVE-2015-7466 [LOW] CWE-74 CVE-2015-7466: Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix0
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended query restrictions or modify the LDAP directory, via unspecified vectors.
nvd
← Previous3 / 3