CVE-2018-1639
https://notcve.org/view.php?id=CVE-2018-1639
The Report Builder of Jazz Reporting Service 5.0 through 5.0.2 and 6.0 through 6.0.6 could allow an authenticated user to obtain sensitive information beyond its assigned privileges. IBM X-Force ID: 144579. Report Builder en Jazz Reporting Service, de la versión 5.0 hasta la 5.0.2 y de la versión 6.0 hasta la 6.0.6, podría permitir que un usuario autenticado obtenga información sensible más allá de sus privilegios asignados. IBM X-Force ID: 144579. • https://exchange.xforce.ibmcloud.com/vulnerabilities/144579 https://www.ibm.com/support/docview.wss?uid=ibm10731727 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-1750
https://notcve.org/view.php?id=CVE-2017-1750
IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 135523. IBM Jazz Reporting Service (JRS), de la versión 5.0 a la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • http://www.ibm.com/support/docview.wss?uid=swg22015712 http://www.securityfocus.com/bid/104012 https://exchange.xforce.ibmcloud.com/vulnerabilities/135523 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-1363
https://notcve.org/view.php?id=CVE-2018-1363
IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137448. IBM Jazz Reporting Service (JRS), de la versión 5.0 a la 5.0.2 y desde la versión 6.0 hasta la 6.0.5, es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • http://www.ibm.com/support/docview.wss?uid=swg22015712 http://www.securityfocus.com/bid/104014 https://exchange.xforce.ibmcloud.com/vulnerabilities/137448 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-1490
https://notcve.org/view.php?id=CVE-2017-1490
An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information. Existe una vulnerabilidad en el motor de consulta de ciclo de vida de Jazz Reporting Service en sus versiones de la 6.0 a la 6.0.4 que podría revelar información sumamente sensible. • http://www.ibm.com/support/docview.wss?uid=swg22008253 http://www.securityfocus.com/bid/100835 https://exchange.xforce.ibmcloud.com/vulnerabilities/128688 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-1370
https://notcve.org/view.php?id=CVE-2017-1370
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863. IBM Jazz Reporting Service (JRS) versiones 5.0 y 6.0, podría revelar información confidencial, incluyendo las credenciales de usuario, por medio de un mensaje de error de la página de configuración del administrador de Report Builder. ID de IBM X-Force: 126863. • http://www.ibm.com/support/docview.wss?uid=swg22005868 http://www.securityfocus.com/bid/99954 https://exchange.xforce.ibmcloud.com/vulnerabilities/126863 • CWE-209: Generation of Error Message Containing Sensitive Information •