CVE-2025-27550: IBM Jazz Reporting Service Information Disclosure

Published Feb 4, 2026
·
Updated

IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server.

Affected Software

29 affected components
IBM Jazz Reporting Service
IBM Jazz Reporting Service=7.0.3
IBM Jazz Reporting Service=7.0.3-ifix001
IBM Jazz Reporting Service=7.0.3-ifix002
IBM Jazz Reporting Service=7.0.3-ifix003
IBM Jazz Reporting Service=7.0.3-ifix004
IBM Jazz Reporting Service=7.0.3-ifix005
IBM Jazz Reporting Service=7.0.3-ifix006
IBM Jazz Reporting Service=7.0.3-ifix007
IBM Jazz Reporting Service=7.0.3-ifix008
IBM Jazz Reporting Service=7.0.3-ifix009
IBM Jazz Reporting Service=7.0.3-ifix010
IBM Jazz Reporting Service=7.0.3-ifix011
IBM Jazz Reporting Service=7.0.3-ifix012
IBM Jazz Reporting Service=7.0.3-ifix013
IBM Jazz Reporting Service=7.0.3-ifix014
IBM Jazz Reporting Service=7.0.3-ifix015
IBM Jazz Reporting Service=7.0.3-ifix016
IBM Jazz Reporting Service=7.0.3-ifix017
IBM Jazz Reporting Service=7.0.3-ifix018
IBM Jazz Reporting Service=7.0.3-ifix019
IBM Jazz Reporting Service=7.0.3-ifix020
IBM Jazz Reporting Service=7.1
IBM Jazz Reporting Service=7.1-ifix001
IBM Jazz Reporting Service=7.1-ifix002
IBM Jazz Reporting Service=7.1-ifix003
IBM Jazz Reporting Service=7.1-ifix004-sr1-base
IBM Jazz Reporting Service=7.1-ifix005
IBM Jazz Reporting Service=7.1-ifix006

Remediation

Information

IBM strongly recommends addressing the vulnerability now by applying the iFix listed below: ProductVersioniFixRemediation / First FixIBM Jazz Reporting Service7.17.1iFix007 Fix Central - 7.1 https://www.ibm.com/support/fixcentral/swg/downloadFixes IBM Jazz Reporting Service7.0.37.0.3iFix021 Fix Central - 7.0.3 https://www.ibm.com/support/fixcentral/swg/doSelectFixes

Event History

Feb 4, 2026
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-27550?

CVE-2025-27550 has a severity rating that indicates a significant risk of information disclosure to authenticated users.

2

How do I fix CVE-2025-27550?

To mitigate CVE-2025-27550, apply the latest patches and updates provided by IBM for the Jazz Reporting Service.

3

Who is affected by CVE-2025-27550?

CVE-2025-27550 affects authenticated users on the host network of IBM Jazz Reporting Service installations.

4

What type of information can be disclosed due to CVE-2025-27550?

CVE-2025-27550 may allow users to obtain sensitive information about other projects hosted on the IBM Jazz Reporting Service server.

5

Is there a workaround for CVE-2025-27550?

Currently, the recommended approach is to update to the latest version of IBM Jazz Reporting Service to address CVE-2025-27550.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203