CVE-2015-7465: CSRF
Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7465?
CVE-2015-7465 is classified as a moderate severity vulnerability due to its potential for authenticated user exploitation.
How do I fix CVE-2015-7465?
To mitigate CVE-2015-7465, you should apply the appropriate IBM Jazz Reporting Service updates provided in the latest patches.
Who is affected by CVE-2015-7465?
CVE-2015-7465 affects users of IBM Jazz Reporting Service 6.0 prior to version 6.0.0-Rational-CLM-ifix005.
What types of attacks can CVE-2015-7465 facilitate?
CVE-2015-7465 can facilitate cross-site request forgery (CSRF) attacks that hijack user sessions and allow the execution of arbitrary requests.
What are the potential impacts of CVE-2015-7465?
The potential impacts of CVE-2015-7465 include unauthorized actions taken on behalf of authenticated users, including execution of XSS attacks.