Input validation error in Jazz Reporting Service - CVE-2016-0314

 

Input validation error in Jazz Reporting Service - CVE-2016-0314

Published: July 8, 2016 / Updated: August 9, 2020


Vulnerability identifier: #VU40209
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2016-0314
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: IBM Corporation
Affected software:
Jazz Reporting Service

Detailed vulnerability description

The vulnerability allows a remote authenticated user to manipulate data.

The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allow remote authenticated users to conduct clickjacking attacks via unspecified vectors.


How to mitigate CVE-2016-0314

Install update from vendor's website.

Sources