CVE-2018-1639: Infoleak
Published Nov 14, 2018
·Updated
The Report Builder of Jazz Reporting Service 5.0 through 5.0.2 and 6.0 through 6.0.6 could allow an authenticated user to obtain sensitive information beyond its assigned privileges. IBM X-Force ID: 144579.
Affected Software
3 affected components
IBM Jazz Reporting Service>=5.0<=5.0.2
IBM Jazz Reporting Service>=6.0<=6.0.2
IBM Jazz Reporting Service>=6.0.3<=6.0.6
Event History
Nov 16, 2018
CVE Published
03:29 PM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2018-1639?
CVE-2018-1639 is a vulnerability found in the Report Builder of the Jazz Reporting Service.
2
What is the severity of CVE-2018-1639?
The severity of CVE-2018-1639 is medium with a severity value of 6.5.
3
How does CVE-2018-1639 affect IBM Jazz Reporting Service?
CVE-2018-1639 affects versions 5.0 through 5.0.2 and 6.0 through 6.0.6 of IBM Jazz Reporting Service.
4
How can an authenticated user exploit CVE-2018-1639?
An authenticated user can exploit CVE-2018-1639 to obtain sensitive information beyond its assigned privileges.
5
How can I fix CVE-2018-1639?
To fix CVE-2018-1639, it is recommended to apply the necessary patches or updates provided by IBM Jazz Reporting Service.