CVE-2017-1157: Infoleak
Published Jul 5, 2017
·Updated
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report data that should be restricted to authorized users. IBM X-Force ID: 122788.
Affected Software
2 affected components
IBM Jazz Reporting Service=5.0
IBM Jazz Reporting Service=6.0
Event History
Jul 5, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1157?
CVE-2017-1157 has a medium severity rating as it allows authenticated attackers to access restricted report data.
2
How do I fix CVE-2017-1157?
To fix CVE-2017-1157, you should upgrade to a patched version of IBM Jazz Reporting Service.
3
What is affected by CVE-2017-1157?
CVE-2017-1157 affects IBM Jazz Reporting Service versions 5.0 and 6.0.
4
Who is impacted by CVE-2017-1157?
Authenticated users with limited access privileges may be impacted by CVE-2017-1157 as it could allow them to access sensitive report data.
5
What type of vulnerability is CVE-2017-1157?
CVE-2017-1157 is an access control vulnerability allowing unauthorized data access.