cbcvebase.

Ibm Jazz Reporting Service vulnerabilities

55 known vulnerabilities affecting ibm/jazz_reporting_service.

Total CVEs
55
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH7MEDIUM43LOW4

Vulnerabilities

Page 3 of 3
CVE-2016-9989P4MEDIUMCVSS 5.4v5.0v5.0.1+5 more2017-07-05
CVE-2016-9989 [MEDIUM] CWE-79 CVE-2016-9989: IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120555.
nvd
CVE-2016-9988P4MEDIUMCVSS 5.4v5.0v5.0.1+5 more2017-07-05
CVE-2016-9988 [MEDIUM] CWE-79 CVE-2016-9988: IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120554.
nvd
CVE-2015-7467P4MEDIUMCVSS 5.4v5.0v5.0.1+2 more2016-01-17
CVE-2015-7467 [MEDIUM] CWE-79 CVE-2015-7467: Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz Reporting Service (JRS) 5.x b Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2016-0316P4MEDIUMCVSS 5.4v6.0v6.0.1+1 more2016-11-25
CVE-2016-0316 [MEDIUM] CWE-79 CVE-2016-0316: Cross-site scripting (XSS) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Servi Cross-site scripting (XSS) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 and 6.0.2 before iFix003 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2017-1370P4MEDIUMCVSS 4.9v5.0v5.0.1+6 more2017-07-31
CVE-2017-1370 [MEDIUM] CWE-209 CVE-2017-1370: IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user cr IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863.
nvd
CVE-2019-4047P4MEDIUMCVSS 4.3v6.0.62019-04-29
CVE-2019-4047 [MEDIUM] CWE-269 CVE-2019-4047: IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest user, and obtain the information of the server execution. IBM X-Force ID: 156243.
nvd
CVE-2015-7468P4MEDIUMCVSS 4.3v5.0v5.0.1+2 more2016-01-17
CVE-2015-7468 [MEDIUM] CWE-264 CVE-2015-7468: Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 bef Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended restrictions on administrator tasks via unspecified vectors.
nvd
CVE-2017-1157P4MEDIUMCVSS 4.3v5.0v6.0+5 more2017-07-05
CVE-2017-1157 [MEDIUM] CWE-200 CVE-2017-1157: IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report data that should be restricted to authorized users. IBM X-Force ID: 122788.
nvd
CVE-2015-7469P4MEDIUMCVSS 4.3v5.0v5.0.1+2 more2016-01-17
CVE-2015-7469 [MEDIUM] CWE-264 CVE-2015-7469: Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 bef Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended read-only restrictions by leveraging a JazzGuest role.
nvd
CVE-2016-5898P4MEDIUMCVSS 4.3v5.0v5.0.1+4 more2017-02-01
CVE-2016-5898 [MEDIUM] CWE-254 CVE-2016-5898: IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caus IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caused by not restricting JSON serialization. By sending a direct request, an attacker could exploit this vulnerability to obtain sensitive information.
nvd
CVE-2024-25052P4MEDIUMCVSS 4.4v7.0.32024-06-13
CVE-2024-25052 [MEDIUM] CWE-256 CVE-2024-25052: IBM Jazz Reporting Service 7.0.3 stores user credentials in plain clear text which can be read by an IBM Jazz Reporting Service 7.0.3 stores user credentials in plain clear text which can be read by an admin user. IBM X-Force ID: 283363.
nvd
CVE-2025-1823P4LOWCVSS 3.5v7.0.3v7.1+2 more2026-02-04
CVE-2025-1823 [LOW] CWE-770 CVE-2025-1823: IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial o IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resources.
nvd
CVE-2025-2134P4LOWCVSS 3.5v7.0.3v7.1+2 more2026-02-04
CVE-2025-2134 [LOW] CWE-410 CVE-2025-2134: IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's p IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.
nvd
CVE-2025-27550P4LOWCVSS 3.5v7.0.3v7.1+2 more2026-02-04
CVE-2025-27550 [LOW] CWE-497 CVE-2025-27550: IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server.
nvd
CVE-2015-7466P4LOWCVSS 3.1v6.02016-01-10
CVE-2015-7466 [LOW] CWE-74 CVE-2015-7466: Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix0 Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended query restrictions or modify the LDAP directory, via unspecified vectors.
nvd
Ibm Jazz Reporting Service vulnerabilities | cvebase