CVE-2021-20535: SSRF
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 198834.
Other sources
IBM Jazz Reporting Service is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-20535.
What is the severity of CVE-2021-20535?
The severity of CVE-2021-20535 is medium with a CVSS score of 6.5.
How does CVE-2021-20535 impact IBM Jazz Reporting Service?
CVE-2021-20535 allows an authenticated attacker to send unauthorized requests, potentially leading to network enumeration or facilitating other attacks.
How can I fix CVE-2021-20535?
To fix CVE-2021-20535, apply the appropriate patch provided by IBM for the affected versions of Jazz Reporting Service.
Where can I find more information about CVE-2021-20535?
You can find more information about CVE-2021-20535 on the IBM X-Force ID page (https://exchange.xforce.ibmcloud.com/vulnerabilities/198834) and the IBM support page (https://www.ibm.com/support/pages/node/6452323).