Ibm Jazz Reporting Service vulnerabilities
55 known vulnerabilities affecting ibm/jazz_reporting_service.
Total CVEs
55
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH7MEDIUM43LOW4
Vulnerabilities
Page 3 of 3
CVE-2016-9989P4MEDIUMCVSS 5.4v5.0v5.0.1+5 more2017-07-05
CVE-2016-9989 [MEDIUM] CWE-79 CVE-2016-9989: IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120555.
nvd
CVE-2016-9988P4MEDIUMCVSS 5.4v5.0v5.0.1+5 more2017-07-05
CVE-2016-9988 [MEDIUM] CWE-79 CVE-2016-9988: IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120554.
nvd
CVE-2015-7467P4MEDIUMCVSS 5.4v5.0v5.0.1+2 more2016-01-17
CVE-2015-7467 [MEDIUM] CWE-79 CVE-2015-7467: Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz Reporting Service (JRS) 5.x b
Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2016-0316P4MEDIUMCVSS 5.4v6.0v6.0.1+1 more2016-11-25
CVE-2016-0316 [MEDIUM] CWE-79 CVE-2016-0316: Cross-site scripting (XSS) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Servi
Cross-site scripting (XSS) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 and 6.0.2 before iFix003 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2017-1370P4MEDIUMCVSS 4.9v5.0v5.0.1+6 more2017-07-31
CVE-2017-1370 [MEDIUM] CWE-209 CVE-2017-1370: IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user cr
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863.
nvd
CVE-2019-4047P4MEDIUMCVSS 4.3v6.0.62019-04-29
CVE-2019-4047 [MEDIUM] CWE-269 CVE-2019-4047: IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log
IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest user, and obtain the information of the server execution. IBM X-Force ID: 156243.
nvd
CVE-2015-7468P4MEDIUMCVSS 4.3v5.0v5.0.1+2 more2016-01-17
CVE-2015-7468 [MEDIUM] CWE-264 CVE-2015-7468: Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 bef
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended restrictions on administrator tasks via unspecified vectors.
nvd
CVE-2017-1157P4MEDIUMCVSS 4.3v5.0v6.0+5 more2017-07-05
CVE-2017-1157 [MEDIUM] CWE-200 CVE-2017-1157: IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report data that should be restricted to authorized users. IBM X-Force ID: 122788.
nvd
CVE-2015-7469P4MEDIUMCVSS 4.3v5.0v5.0.1+2 more2016-01-17
CVE-2015-7469 [MEDIUM] CWE-264 CVE-2015-7469: Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 bef
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended read-only restrictions by leveraging a JazzGuest role.
nvd
CVE-2016-5898P4MEDIUMCVSS 4.3v5.0v5.0.1+4 more2017-02-01
CVE-2016-5898 [MEDIUM] CWE-254 CVE-2016-5898: IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caus
IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caused by not restricting JSON serialization. By sending a direct request, an attacker could exploit this vulnerability to obtain sensitive information.
nvd
CVE-2024-25052P4MEDIUMCVSS 4.4v7.0.32024-06-13
CVE-2024-25052 [MEDIUM] CWE-256 CVE-2024-25052: IBM Jazz Reporting Service 7.0.3 stores user credentials in plain clear text which can be read by an
IBM Jazz Reporting Service 7.0.3 stores user credentials in plain clear text which can be read by an admin user. IBM X-Force ID: 283363.
nvd
CVE-2025-1823P4LOWCVSS 3.5v7.0.3v7.1+2 more2026-02-04
CVE-2025-1823 [LOW] CWE-770 CVE-2025-1823: IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial o
IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resources.
nvd
CVE-2025-2134P4LOWCVSS 3.5v7.0.3v7.1+2 more2026-02-04
CVE-2025-2134 [LOW] CWE-410 CVE-2025-2134: IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's p
IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.
nvd
CVE-2025-27550P4LOWCVSS 3.5v7.0.3v7.1+2 more2026-02-04
CVE-2025-27550 [LOW] CWE-497 CVE-2025-27550: IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive
IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server.
nvd
CVE-2015-7466P4LOWCVSS 3.1v6.02016-01-10
CVE-2015-7466 [LOW] CWE-74 CVE-2015-7466: Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix0
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended query restrictions or modify the LDAP directory, via unspecified vectors.
nvd
← Previous3 / 3