First published: Wed May 12 2021(Updated: )
IBM Jazz Reporting Service is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz Reporting Service | <=7.0.2 | |
IBM Jazz Reporting Service | <=7.0.1 | |
IBM Jazz Reporting Service | <=7.0 | |
IBM Jazz Reporting Service | <=6.0.6.1 | |
IBM Jazz Reporting Service | =6.0.6.1 | |
IBM Jazz Reporting Service | =7.0 | |
IBM Jazz Reporting Service | =7.0.1 | |
IBM Jazz Reporting Service | =7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-20535.
The severity of CVE-2021-20535 is medium with a CVSS score of 6.5.
CVE-2021-20535 allows an authenticated attacker to send unauthorized requests, potentially leading to network enumeration or facilitating other attacks.
To fix CVE-2021-20535, apply the appropriate patch provided by IBM for the affected versions of Jazz Reporting Service.
You can find more information about CVE-2021-20535 on the IBM X-Force ID page (https://exchange.xforce.ibmcloud.com/vulnerabilities/198834) and the IBM support page (https://www.ibm.com/support/pages/node/6452323).