CVE-2017-1157
https://notcve.org/view.php?id=CVE-2017-1157
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report data that should be restricted to authorized users. IBM X-Force ID: 122788. Jazz Reporting Service (JRS) versiones 5.0 y 6.0 de IBM, podría permitir a un atacante identificado acceder a datos de informes que deberían estar restringidos a usuarios autorizados. ID de IBM X-Force: 122788. • http://www.ibm.com/support/docview.wss?uid=swg22001007 http://www.securityfocus.com/bid/99353 https://exchange.xforce.ibmcloud.com/vulnerabilities/122778 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-9986
https://notcve.org/view.php?id=CVE-2016-9986
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120552. IBM Jazz Foundation Reporting Service (JRS) versiones 5.0 y 6.0, es vulnerable a un problema de tipo cross-site scripting. Esta vulnerabilidad permite a los usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario Web, y por lo tanto, alterar la funcionalidad deseada conllevando potencialmente a la divulgación de credenciales dentro de una sesión confiable. • http://www.ibm.com/support/docview.wss?uid=swg22001007 http://www.securityfocus.com/bid/99353 https://exchange.xforce.ibmcloud.com/vulnerabilities/120552 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2016-6039
https://notcve.org/view.php?id=CVE-2016-6039
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Jazz Reporting Service (JRS) es vulnerable a las secuencias de comandos de sitios cruzados. Esta vulnerabilidad permite a usuarios incrustar código JavaScript arbitrario en la IU Web alterando así la funcionalidad prevista que potencialmente conduce a la divulgación de credenciales dentro de una sesión de confianza. • http://www.ibm.com/support/docview.wss?uid=swg21991153 http://www.securityfocus.com/bid/94853 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2016-6054
https://notcve.org/view.php?id=CVE-2016-6054
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Jazz Foundation es vulnerable a las secuencias de comandos de sitios cruzados. Esta vulnerabilidad permite a usuarios incrustar código JavaScript arbitrario en la IU Web alterando así la funcionalidad prevista que potencialmente conduce a la divulgación de credenciales dentro de una sesión de confianza. • http://www.ibm.com/support/docview.wss?uid=swg21991154 http://www.securityfocus.com/bid/94842 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2016-5897
https://notcve.org/view.php?id=CVE-2016-5897
IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM Jazz Reporting Service (JRS) es vulnerable a inyección HTML. Un atacante remoto podría inyectar código HTML malicioso, que al ser visto, sería ejecutado en el navegador Web de la víctima dentro del contexto de seguridad del sitio de alojamiento. • http://www.ibm.com/support/docview.wss?uid=swg21991153 http://www.securityfocus.com/bid/94857 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •