CVE-2016-9989: XSS
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120555.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9989?
CVE-2016-9989 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2016-9989?
To fix CVE-2016-9989, upgrade the IBM Jazz Reporting Service to a patched version that addresses the cross-site scripting vulnerability.
What versions of IBM Jazz Reporting Service are affected by CVE-2016-9989?
CVE-2016-9989 affects IBM Jazz Reporting Service versions 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, 6.0.2, and 6.0.3.
What type of attack does CVE-2016-9989 allow?
CVE-2016-9989 allows attackers to perform cross-site scripting, potentially leading to credential disclosure.
Can CVE-2016-9989 affect users with trusted sessions?
Yes, CVE-2016-9989 can affect users with trusted sessions, allowing for potential credential disclosure.