First published: Wed Jan 08 2020(Updated: )
IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170962.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz Reporting Service | =6.0.6.1 | |
<=6.0.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4651 is critical with a severity value of 9.8.
CVE-2019-4651 allows a remote attacker to perform SQL injection and potentially view, add, modify, or delete information in the back-end database of IBM Jazz Reporting Service (JRS) version 6.0.6.1.
CVE-2019-4651 is associated with CWE-89, which represents SQL injection vulnerabilities.
To patch the vulnerability, you can download the necessary fix from the IBM support page: [link](https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Rational&product=ibm%2FRational%2FRational+Collaborative+Lifecycle+Management+Solution&release=6.0.6.1&platform=All&function=all)
You can find more information about CVE-2019-4651 on the IBM X-Force Exchange page: [link](https://exchange.xforce.ibmcloud.com/vulnerabilities/170962)