First published: Wed May 12 2021(Updated: )
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 198834.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz Reporting Service | =6.0.6.1 | |
IBM Jazz Reporting Service | =7.0 | |
IBM Jazz Reporting Service | =7.0.1 | |
IBM Jazz Reporting Service | =7.0.2 | |
<=7.0.2 | ||
<=7.0.1 | ||
<=7.0 | ||
<=6.0.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-20535.
The severity of CVE-2021-20535 is medium with a CVSS score of 6.5.
CVE-2021-20535 allows an authenticated attacker to send unauthorized requests, potentially leading to network enumeration or facilitating other attacks.
To fix CVE-2021-20535, apply the appropriate patch provided by IBM for the affected versions of Jazz Reporting Service.
You can find more information about CVE-2021-20535 on the IBM X-Force ID page (https://exchange.xforce.ibmcloud.com/vulnerabilities/198834) and the IBM support page (https://www.ibm.com/support/pages/node/6452323).