Cross-site scripting in Jazz Reporting Service - CVE-2016-5897

 

Cross-site scripting in Jazz Reporting Service - CVE-2016-5897

Published: February 1, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU39756
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2016-5897
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to read and manipulate data.

IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.


Affected software

Jazz Reporting Service

How to mitigate CVE-2016-5897

Install update from vendor's website.


External References

Related Security Bulletins