First published: Sun Jan 17 2016(Updated: )
Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz Reporting Service | =5.0 | |
IBM Jazz Reporting Service | =5.0.1 | |
IBM Jazz Reporting Service | =5.0.2 | |
IBM Jazz Reporting Service | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7467 has been classified as a medium severity vulnerability due to its potential impact on user data and application integrity.
To fix CVE-2015-7467, upgrade IBM Jazz Reporting Service to versions 5.0.2-Rational-CLM-ifix011 or later, or 6.0.0-Rational-CLM-ifix005 or later.
CVE-2015-7467 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts or HTML.
CVE-2015-7467 affects remote authenticated users of IBM Jazz Reporting Service versions prior to 5.0.2-Rational-CLM-ifix011 and 6.0.0-Rational-CLM-ifix005.
No, CVE-2015-7467 requires an authenticated user to exploit the XSS vulnerability through a crafted URL.