CVE-2016-0318: Medium severity ibm jazz reporting service vulnerability
Published Nov 25, 2016
·Updated
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, which allows remote attackers to obtain access by leveraging an unattended workstation.
Affected Software
2 affected components
IBM Jazz Reporting Service=6.0
IBM Jazz Reporting Service=6.0.1
Remediation
Patch Available
Event History
Nov 25, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0318?
CVE-2016-0318 is classified as a medium severity vulnerability due to its potential to allow session hijacking.
2
How do I fix CVE-2016-0318?
To fix CVE-2016-0318, update IBM Jazz Reporting Service to version 6.0.1 iFix006 or later.
3
What impact does CVE-2016-0318 have on security?
CVE-2016-0318 may allow an attacker to gain unauthorized access to an account that remains logged in.
4
Is CVE-2016-0318 exploitable remotely?
Yes, attackers can exploit CVE-2016-0318 remotely if they gain access to an unattended workstation.
5
What products are affected by CVE-2016-0318?
CVE-2016-0318 affects IBM Jazz Reporting Service versions 6.0 and 6.0.1 before fix iFix006.