CVE-2016-2888: XSS
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0313 and CVE-2016-0350.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2888?
CVE-2016-2888 is rated as a medium severity vulnerability due to the potential for remote authenticated users to inject malicious web scripts.
How do I fix CVE-2016-2888?
To fix CVE-2016-2888, update IBM Jazz Reporting Service to version 5.0.2 ifix016 or 6.0.1 ifix005 or later.
What components are affected by CVE-2016-2888?
CVE-2016-2888 affects the Report Builder and Data Collection Component within IBM Jazz Reporting Service versions 5.x before 5.0.2 and 6.x before 6.0.1.
Who can exploit CVE-2016-2888?
CVE-2016-2888 can be exploited by remote authenticated users who have access to the affected IBM Jazz Reporting Service.
What type of vulnerability is CVE-2016-2888?
CVE-2016-2888 is a cross-site scripting (XSS) vulnerability that allows user-entered data to be executed as code.