CVE-2016-2889: CSRF
Cross-site request forgery (CSRF) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016, 6.0 and 6.0.1 before 6.0.1 ifix005, and 6.0.2 before ifix002 allows remote authenticated users to hijack the authentication of arbitrary users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2889?
The severity of CVE-2016-2889 is considered high due to its potential for unauthorized access and data manipulation.
How do I fix CVE-2016-2889?
To fix CVE-2016-2889, upgrade IBM Jazz Reporting Service to version 5.0.2 ifix016, 6.0.1 ifix005, or 6.0.2 ifix002 or later.
Who is affected by CVE-2016-2889?
CVE-2016-2889 affects users of IBM Jazz Reporting Service versions 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, and 6.0.2 prior to their respective fixes.
What type of vulnerability is CVE-2016-2889?
CVE-2016-2889 is classified as a Cross-site request forgery (CSRF) vulnerability.
Can CVE-2016-2889 be exploited remotely?
Yes, CVE-2016-2889 can be exploited by remote authenticated users to hijack sessions.