
CVE-2017-1340
https://notcve.org/view.php?id=CVE-2017-1340
01 Nov 2017 — IBM Jazz Reporting Service (JRS) 6.0.4 could allow an authenticated user to obtain information on another server that the current report builder interacts with. IBM X-Force ID: 126455. Jazz Reporting Service (JRS) de IBM 6.0.4 podría permitir que un usuario autenticado obtenga información de otro usuario con el que interactúa el creador de informes . IBM X-Force ID: 126455. • http://www.ibm.com/support/docview.wss?uid=swg22009973 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-1490
https://notcve.org/view.php?id=CVE-2017-1490
14 Sep 2017 — An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information. Existe una vulnerabilidad en el motor de consulta de ciclo de vida de Jazz Reporting Service en sus versiones de la 6.0 a la 6.0.4 que podría revelar información sumamente sensible. • http://www.ibm.com/support/docview.wss?uid=swg22008253 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-1370
https://notcve.org/view.php?id=CVE-2017-1370
31 Jul 2017 — IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863. IBM Jazz Reporting Service (JRS) versiones 5.0 y 6.0, podría revelar información confidencial, incluyendo las credenciales de usuario, por medio de un mensaje de error de la página de configuración del administrador de Report Builder. ID de IBM X-Force: 126863. • http://www.ibm.com/support/docview.wss?uid=swg22005868 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2017-1157
https://notcve.org/view.php?id=CVE-2017-1157
05 Jul 2017 — IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report data that should be restricted to authorized users. IBM X-Force ID: 122788. Jazz Reporting Service (JRS) versiones 5.0 y 6.0 de IBM, podría permitir a un atacante identificado acceder a datos de informes que deberían estar restringidos a usuarios autorizados. ID de IBM X-Force: 122788. • http://www.ibm.com/support/docview.wss?uid=swg22001007 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-1096
https://notcve.org/view.php?id=CVE-2017-1096
05 Jul 2017 — IBM Jazz Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120656. IBM Jazz Reporting Service (JRS) 5.0 y 6.0 es vulnerable a Cross-Site Scripting. Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera la... • http://www.ibm.com/support/docview.wss?uid=swg22001007 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-9986
https://notcve.org/view.php?id=CVE-2016-9986
05 Jul 2017 — IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120552. IBM Jazz Foundation Reporting Service (JRS) versiones 5.0 y 6.0, es vulnerable a un problema de tipo cross-site scripting. Esta vulnerabilidad permite a los usuarios insertar código JavaScript arbitr... • http://www.ibm.com/support/docview.wss?uid=swg22001007 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-9987
https://notcve.org/view.php?id=CVE-2016-9987
05 Jul 2017 — IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120553. IBM Jazz Foundation Reporting Service (JRS) 5.0 y 6.0 es vulnerables a Cross-Site Scripting. Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbitrario en el WEB UI, de este mo... • http://www.ibm.com/support/docview.wss?uid=swg22001007 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-9988
https://notcve.org/view.php?id=CVE-2016-9988
05 Jul 2017 — IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120554. IBM Jazz Foundation Reporting Service (JRS) versiones 5.0 y 6.0, es vulnerable a un problema de tipo cross-site scripting. Esta vulnerabilidad permite a los usuarios insertar código JavaScript arbitr... • http://www.ibm.com/support/docview.wss?uid=swg22001007 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-9989
https://notcve.org/view.php?id=CVE-2016-9989
05 Jul 2017 — IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120555. IBM Jazz Foundation Reporting Service (JRS) versiones 5.0 y 6.0, es vulnerable a un problema de tipo cross-site scripting. Esta vulnerabilidad permite a los usuarios insertar código JavaScript arbitr... • http://www.ibm.com/support/docview.wss?uid=swg22001007 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-5897
https://notcve.org/view.php?id=CVE-2016-5897
01 Feb 2017 — IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM Jazz Reporting Service (JRS) es vulnerable a inyección HTML. Un atacante remoto podría inyectar código HTML malicioso, que al ser visto, sería ejecutado en el navegador Web de la víctima dentro del contexto de seguridad del sitio de alojamiento. • http://www.ibm.com/support/docview.wss?uid=swg21991153 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •