CVE-2019-4651: SQL Injection
IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170962.
Other sources
IBM Jazz Reporting Service (JRS) is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4651?
The severity of CVE-2019-4651 is critical with a severity value of 9.8.
How does CVE-2019-4651 affect IBM Jazz Reporting Service (JRS)?
CVE-2019-4651 allows a remote attacker to perform SQL injection and potentially view, add, modify, or delete information in the back-end database of IBM Jazz Reporting Service (JRS) version 6.0.6.1.
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2019-4651?
CVE-2019-4651 is associated with CWE-89, which represents SQL injection vulnerabilities.
How can I patch the vulnerability in IBM Jazz Reporting Service (JRS) version 6.0.6.1?
To patch the vulnerability, you can download the necessary fix from the IBM support page: [link](https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Rational&product=ibm%2FRational%2FRational+Collaborative+Lifecycle+Management+Solution&release=6.0.6.1&platform=All&function=all)
Where can I find more information about CVE-2019-4651?
You can find more information about CVE-2019-4651 on the IBM X-Force Exchange page: [link](https://exchange.xforce.ibmcloud.com/vulnerabilities/170962)