Permissions, Privileges, and Access Controls in Jazz Reporting Service - CVE-2015-7469
Published: January 17, 2016 / Updated: August 9, 2020
Jazz Reporting Service
Detailed vulnerability description
The vulnerability allows a remote authenticated user to manipulate data.
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended read-only restrictions by leveraging a JazzGuest role.