First published: Fri Jul 08 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0313.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz Reporting Service | =5.0 | |
IBM Jazz Reporting Service | =5.0.1 | |
IBM Jazz Reporting Service | =5.0.2 | |
IBM Jazz Reporting Service | =6.0 | |
IBM Jazz Reporting Service | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0350 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2016-0350, update your IBM Jazz Reporting Service to version 5.0.2 ifix016 or 6.0.1 ifix005 or later.
CVE-2016-0350 affects IBM Jazz Reporting Service versions 5.0 to 5.0.1 and 6.0 to 6.0.1 before the respective fixes.
CVE-2016-0350 allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted URLs.
No, CVE-2016-0350 requires remote authenticated access to enable exploitation of the vulnerability.