Input validation error in Jazz Reporting Service - CVE-2016-0314
Published: July 8, 2016 / Updated: August 9, 2020
Vulnerability identifier: #VU40209
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2016-0314
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: IBM Corporation
Affected software:
Jazz Reporting Service
Jazz Reporting Service
Detailed vulnerability description
The vulnerability allows a remote authenticated user to manipulate data.
The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allow remote authenticated users to conduct clickjacking attacks via unspecified vectors.
How to mitigate CVE-2016-0314
Install update from vendor's website.