CVE-2016-0350: XSS
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0313.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0350?
CVE-2016-0350 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2016-0350?
To fix CVE-2016-0350, update your IBM Jazz Reporting Service to version 5.0.2 ifix016 or 6.0.1 ifix005 or later.
Who is affected by CVE-2016-0350?
CVE-2016-0350 affects IBM Jazz Reporting Service versions 5.0 to 5.0.1 and 6.0 to 6.0.1 before the respective fixes.
What type of attack is possible with CVE-2016-0350?
CVE-2016-0350 allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted URLs.
Can CVE-2016-0350 be exploited without authentication?
No, CVE-2016-0350 requires remote authenticated access to enable exploitation of the vulnerability.