2 results (0.002 seconds)

CVSS: 6.5EPSS: 0%CPEs: 4EXPL: 0

13 May 2021 — IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 198834. IBM Jazz Reporting Service versiones 6.0.6.1, 7.0, 7.0.1 y 7.0.2, es vulnerable a un ataque de tipo server-side request forgery (SSRF). Esto puede permitir a un atacante autenticado enviar peticiones no autoriz... • https://exchange.xforce.ibmcloud.com/vulnerabilities/198834 • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 5.4EPSS: 0%CPEs: 6EXPL: 0

18 Feb 2021 — IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191751. IBM Jazz Reporting Service versiones 6.0.6.1, 7.0, 7.0.1 y 7.0.2, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbi... • https://exchange.xforce.ibmcloud.com/vulnerabilities/191751 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •