Show filters
45 Total Results
Displaying 21-30 of 45
Sort by:
Attacker Value
Unknown

CVE-2017-1157

Disclosure Date: July 05, 2017 (last updated November 26, 2024)
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report data that should be restricted to authorized users. IBM X-Force ID: 122788.
0
Attacker Value
Unknown

CVE-2016-9987

Disclosure Date: July 05, 2017 (last updated November 26, 2024)
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120553.
0
Attacker Value
Unknown

CVE-2016-5899

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown

CVE-2016-6054

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown

CVE-2016-5898

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caused by not restricting JSON serialization. By sending a direct request, an attacker could exploit this vulnerability to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2016-5897

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
0
Attacker Value
Unknown

CVE-2016-6047

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown

CVE-2016-6039

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown

CVE-2016-0317

Disclosure Date: November 25, 2016 (last updated November 25, 2024)
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-0319

Disclosure Date: November 25, 2016 (last updated November 25, 2024)
The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administrators to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
0