- Description
- The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allow remote authenticated users to conduct clickjacking attacks via unspecified vectors.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
CVSS 3.0
- Type
- Primary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:N/I:P/A:N
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:jazz_reporting_service:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D226029-A37F-486C-9DCD-1921671F242D"
},
{
"criteria": "cpe:2.3:a:ibm:jazz_reporting_service:5.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "83152595-8909-4AA4-A7D1-2E113A197B1A"
},
{
"criteria": "cpe:2.3:a:ibm:jazz_reporting_service:5.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "103F9E24-E11F-4BAC-8EDB-86D332B9EC43"
},
{
"criteria": "cpe:2.3:a:ibm:jazz_reporting_service:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "07DD3FB3-ABE3-4645-9AFB-429EA4EA818D"
},
{
"criteria": "cpe:2.3:a:ibm:jazz_reporting_service:6.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF3780DD-9FAC-4850-AA83-DCA7D013FB3E"
}
],
"operator": "OR"
}
]
}
]