CVE-2016-5897: XSS
IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5897?
CVE-2016-5897 is considered a high-severity vulnerability due to the potential for remote code execution through HTML injection.
How do I fix CVE-2016-5897?
To fix CVE-2016-5897, upgrade to a fixed version of IBM Jazz Reporting Service, specifically 6.0.1 or later.
Who is affected by CVE-2016-5897?
Users of IBM Jazz Reporting Service versions 6.0, 6.0.1, and 6.0.2 are affected by CVE-2016-5897.
What type of attack does CVE-2016-5897 enable?
CVE-2016-5897 enables remote attackers to inject arbitrary HTML and execute it in victims' web browsers.
Is CVE-2016-5897 easy to exploit?
Yes, CVE-2016-5897 can be exploited easily if the vulnerable software is exposed to untrusted users.