CVE-2015-7470: Infoleak
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors, as demonstrated by login information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7470?
CVE-2015-7470 has a medium severity rating due to its potential for man-in-the-middle attacks that can expose sensitive information.
How do I fix CVE-2015-7470?
Fix CVE-2015-7470 by upgrading to IBM Jazz Reporting Service version 5.0.2-Rational-CLM-ifix011 or 6.0.0-Rational-CLM-ifix005.
What types of sensitive information can be compromised in CVE-2015-7470?
CVE-2015-7470 potentially allows exposure of sensitive data, including user login credentials, during transmission.
Which versions of IBM Jazz Reporting Service are affected by CVE-2015-7470?
CVE-2015-7470 affects IBM Jazz Reporting Service versions 5.0, 5.0.1, 5.0.2, and 6.0.
What kind of attack does CVE-2015-7470 describe?
CVE-2015-7470 describes a man-in-the-middle attack that allows attackers to intercept sensitive information.