CVE-2015-7467: XSS
Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7467?
CVE-2015-7467 has been classified as a medium severity vulnerability due to its potential impact on user data and application integrity.
How do I fix CVE-2015-7467?
To fix CVE-2015-7467, upgrade IBM Jazz Reporting Service to versions 5.0.2-Rational-CLM-ifix011 or later, or 6.0.0-Rational-CLM-ifix005 or later.
What type of vulnerability is CVE-2015-7467?
CVE-2015-7467 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts or HTML.
Who is affected by CVE-2015-7467?
CVE-2015-7467 affects remote authenticated users of IBM Jazz Reporting Service versions prior to 5.0.2-Rational-CLM-ifix011 and 6.0.0-Rational-CLM-ifix005.
Can CVE-2015-7467 be exploited by unauthenticated users?
No, CVE-2015-7467 requires an authenticated user to exploit the XSS vulnerability through a crafted URL.