First published: Wed Feb 01 2017(Updated: )
IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz Reporting Service | =6.0 | |
IBM Jazz Reporting Service | =6.0.1 | |
IBM Jazz Reporting Service | =6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5897 is considered a high-severity vulnerability due to the potential for remote code execution through HTML injection.
To fix CVE-2016-5897, upgrade to a fixed version of IBM Jazz Reporting Service, specifically 6.0.1 or later.
Users of IBM Jazz Reporting Service versions 6.0, 6.0.1, and 6.0.2 are affected by CVE-2016-5897.
CVE-2016-5897 enables remote attackers to inject arbitrary HTML and execute it in victims' web browsers.
Yes, CVE-2016-5897 can be exploited easily if the vulnerable software is exposed to untrusted users.