First published: Fri Jul 08 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0313 and CVE-2016-0350.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz Reporting Service | =5.0 | |
IBM Jazz Reporting Service | =5.0.1 | |
IBM Jazz Reporting Service | =5.0.2 | |
IBM Jazz Reporting Service | =6.0 | |
IBM Jazz Reporting Service | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2888 is rated as a medium severity vulnerability due to the potential for remote authenticated users to inject malicious web scripts.
To fix CVE-2016-2888, update IBM Jazz Reporting Service to version 5.0.2 ifix016 or 6.0.1 ifix005 or later.
CVE-2016-2888 affects the Report Builder and Data Collection Component within IBM Jazz Reporting Service versions 5.x before 5.0.2 and 6.x before 6.0.1.
CVE-2016-2888 can be exploited by remote authenticated users who have access to the affected IBM Jazz Reporting Service.
CVE-2016-2888 is a cross-site scripting (XSS) vulnerability that allows user-entered data to be executed as code.