First published: Sun Jan 17 2016(Updated: )
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended restrictions on administrator tasks via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz Reporting Service | =5.0 | |
IBM Jazz Reporting Service | =5.0.1 | |
IBM Jazz Reporting Service | =5.0.2 | |
IBM Jazz Reporting Service | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7468 has a medium severity rating due to its potential for remote authenticated users to bypass administrative restrictions.
To mitigate CVE-2015-7468, upgrade to IBM Jazz Reporting Service versions 5.0.2-Rational-CLM-ifix011 or 6.0.0-Rational-CLM-ifix005.
CVE-2015-7468 affects users of IBM Jazz Reporting Service versions 5.0, 5.0.1, and 6.0 before the respective fix versions.
CVE-2015-7468 is identified as an access control vulnerability that allows privilege escalation for authenticated users.
CVE-2015-7468 was reported on November 3, 2015.